GHSA-74cp-qw7f-7hpw

Suggest an improvement
Source
https://github.com/advisories/GHSA-74cp-qw7f-7hpw
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/06/GHSA-74cp-qw7f-7hpw/GHSA-74cp-qw7f-7hpw.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-74cp-qw7f-7hpw
Published
2019-06-05T14:10:23Z
Modified
2020-08-31T18:36:24Z
Summary
Path Traversal in statics-server
Details

All versions of statics-server are vulnerable to Path Traversal. Due to insufficient input sanitization, attackers can access server files by using relative paths.

Recommendation

No fix is currently available. Consider using an alternative module until a fix is made available.

Database specific
{
    "cwe_ids":  [
        "CWE-22"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2019-06-05T13:49:00Z",
    "nvd_published_at":  null,
    "severity":  "MODERATE"
}
References

Affected packages

npm / statics-server

Package

Name
statics-server
View open source insights on deps.dev
Purl
pkg:npm/statics-server

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
0.0.9

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/06/GHSA-74cp-qw7f-7hpw/GHSA-74cp-qw7f-7hpw.json"