GHSA-4vvp-x9h2-x2vf

Suggest an improvement
Source
https://github.com/advisories/GHSA-4vvp-x9h2-x2vf
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-4vvp-x9h2-x2vf/GHSA-4vvp-x9h2-x2vf.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-4vvp-x9h2-x2vf
Published
2020-09-03T20:26:39Z
Modified
2020-08-31T18:48:53Z
Summary
Path Traversal in public
Details

All versions of public are vulnerable to Path Traversal. This vulnerability allows an attacker to access files outside the webroot since it allows symlink navigation in the URL.

Recommendation

No fix is currently available. Do not use public in production or consider using an alternative module until a fix is made available.

Database specific
{
    "cwe_ids":  [
        "CWE-22"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2020-08-31T18:48:53Z",
    "nvd_published_at":  null,
    "severity":  "MODERATE"
}
References

Affected packages

npm / public

Package

Affected ranges

Type
SEMVER
Events
Introduced
0.0.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-4vvp-x9h2-x2vf/GHSA-4vvp-x9h2-x2vf.json"