GHSA-m4vv-p6fq-jhqp

Suggest an improvement
Source
https://github.com/advisories/GHSA-m4vv-p6fq-jhqp
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-m4vv-p6fq-jhqp/GHSA-m4vv-p6fq-jhqp.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-m4vv-p6fq-jhqp
Published
2020-09-01T19:04:07Z
Modified
2021-09-23T21:48:53Z
Summary
Directory Traversal in @vivaxy/here
Details

The @vivaxy/here module is a small web server that serves files with the process' working directory acting as the web root.

It is vulnerable to a directory traversal attack.

This means that files on the local file system which exist outside of the web root may be disclosed to an attacker. This might include confidential files.

Mitigating Factors: If the node process is run as a user with very limited filesystem permissions, there is significantly less risk of exposing confidential/private information.

Proof of Concept:

curl "http://${SERVER_IP}:${SERVER_PORT}/..%2f..%2fetc/passwd"

Recommendation

Run npm i @vivaxy/here to install the latest version that addresses this vulnerability.

Database specific
{
    "cwe_ids":  [
        "CWE-22"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2020-08-31T18:27:40Z",
    "nvd_published_at":  null,
    "severity":  "HIGH"
}
References

Affected packages

npm / @vivaxy/here

Package

Name
@vivaxy/here
View open source insights on deps.dev
Purl
pkg:npm/%40vivaxy/here

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.2.2

Database specific

last_known_affected_version_range
"<= 3.2.1"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-m4vv-p6fq-jhqp/GHSA-m4vv-p6fq-jhqp.json"