GHSA-3r8f-gphx-9m2c

Suggest an improvement
Source
https://github.com/advisories/GHSA-3r8f-gphx-9m2c
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/07/GHSA-3r8f-gphx-9m2c/GHSA-3r8f-gphx-9m2c.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-3r8f-gphx-9m2c
Aliases
  • CVE-2018-3730
Published
2018-07-27T17:04:16Z
Modified
2023-11-08T04:00:17.731763Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
Path Traversal in mcstatic
Details

All versions of mcstatic are vulnerable to path traversal.

Recommendation

No fix is currently available for this vulnerability. It is our recommendation to not install or use this module at this time.

Database specific
{
    "cwe_ids": [
        "CWE-22"
    ],
    "nvd_published_at": "2018-06-07T02:29:00Z",
    "severity": "HIGH",
    "github_reviewed_at": "2020-06-16T20:56:02Z",
    "github_reviewed": true
}
References

Affected packages

npm / mcstatic

Package

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
0.0.20