You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
cve 2024 29041
About this tag
CVE-2024-29041 is an open redirect vulnerability in the Express.js web framework for Node.js. It allows attackers to bypass redirect allow-list checks by supplying malformed URLs that are improperly encoded or normalized by Express's res.location() and res.redirect() methods. Microsoft's advisory lists Azure Linux as a potentially affected product because it includes the vulnerable open-source library, but this does not guarantee that no other Microsoft products are affected. The vulnerability is not exclusive to Azure Linux; any product using the affected Express.js library could be at risk. Users should apply patches or mitigations as recommended by Express.js and Microsoft advisories.
Microsoft’s public advisory correctly identifies Azure Linux as a Microsoft product that “includes this open‑source library and is therefore potentially affected,” but that phrasing is a scoped product attestation — not a technical guarantee that no other Microsoft product could include the...