GHSA-4448-rc82-fcr7

Source
https://github.com/advisories/GHSA-4448-rc82-fcr7
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/09/GHSA-4448-rc82-fcr7/GHSA-4448-rc82-fcr7.json
Aliases
  • CVE-2019-5444
Published
2021-09-22T18:40:57Z
Modified
2023-11-08T04:01:36.349986Z
Details

Versions of serve-here.js prior to 1.2.0 are vulnerable to path traversal. The package fails to sanitize URLs, allowing attackers to access server files outside of the served folder using relative paths.

References

Affected packages

npm / serve-here.js

Package

Affected ranges

Type
SEMVER
Events
Introduced
0The exact introduced commit is unknown
Fixed
1.2.0