diff --git a/advisories/github-reviewed/2025/05/GHSA-4pg4-qvpc-4q3h/GHSA-4pg4-qvpc-4q3h.json b/advisories/github-reviewed/2025/05/GHSA-4pg4-qvpc-4q3h/GHSA-4pg4-qvpc-4q3h.json index 42f2006a5f9a1..84055089692d1 100644 --- a/advisories/github-reviewed/2025/05/GHSA-4pg4-qvpc-4q3h/GHSA-4pg4-qvpc-4q3h.json +++ b/advisories/github-reviewed/2025/05/GHSA-4pg4-qvpc-4q3h/GHSA-4pg4-qvpc-4q3h.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-4pg4-qvpc-4q3h", - "modified": "2025-05-19T22:16:30Z", + "modified": "2025-05-21T20:37:35Z", "published": "2025-05-19T22:16:30Z", "aliases": [ "CVE-2025-47944" ], "summary": "Multer vulnerable to Denial of Service from maliciously crafted requests", - "details": "### Impact\nA vulnerability in Multer versions >=1.4.4-lts.1 allows an attacker to trigger a Denial of Service (DoS) by sending a malformed multi-part upload request. This request causes an unhandled exception, leading to a crash of the process.\n\n### Patches\nUsers should upgrade to `2.0.0`\n\n### Workarounds\nNone\n\n### References\n\n- https://github.com/expressjs/multer/issues/1176\n- https://github.com/expressjs/multer/commit/2c8505f207d923dd8de13a9f93a4563e59933665", + "details": "### Impact\nA vulnerability in Multer versions >=1.4.4-lts.1 allows an attacker to trigger a Denial of Service (DoS) by sending a malformed multi-part upload request. This request causes an unhandled exception, leading to a crash of the process.\n\n### Patches\nUsers should upgrade to `2.0.0`\n\n### Workarounds\nNone\n\n### References\n\n- https://github.com/expressjs/multer/issues/1176\n- https://github.com/expressjs/multer/commit/2c8505f207d923dd8de13a9f93a4563e59933665\n- المراقبة الأمنية الشاملة:\n✅ npm audit → فحص ثغرات npm\n✅ Snyk → فحص أمني متقدم\n✅ GitLeaks → كشف الأسرار المسربة\n✅ Trivy → فحص Docker + Dependencies\n✅ SARIF Upload → رفع للـ GitHub Security", "severity": [ { "type": "CVSS_V3",