CVE-2020-7699: Injection Vulnerability
(updated )
This affects the package express-fileupload. If the parseNested
option is enabled, sending a corrupt HTTP request can lead to denial of service or arbitrary code execution.
References
Detect and mitigate CVE-2020-7699 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →