GHSA-q2qh-cgc2-qhr3

Suggest an improvement
Source
https://github.com/advisories/GHSA-q2qh-cgc2-qhr3
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/07/GHSA-q2qh-cgc2-qhr3/GHSA-q2qh-cgc2-qhr3.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-q2qh-cgc2-qhr3
Aliases
Published
2018-07-27T17:07:50Z
Modified
2023-11-08T04:00:16Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
Directory Traversal in serve
Details

Affected versions of serve do not properly handle %2e (.) and %2f (/) characters, and allow the, characters to be used in paths. This can be used to traverse the directory tree and list content of any directory the user running the process has access to.

Mitigating factors: This vulnerability only allows listing of directory contents and does not allow reading of arbitrary files.

Recommendation

Update to version 6.4.9 later.

Database specific
{
    "cwe_ids":  [
        "CWE-22"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2020-06-16T21:50:26Z",
    "nvd_published_at":  null,
    "severity":  "MODERATE"
}
References

Affected packages

npm / serve

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
6.4.9

Database specific

last_known_affected_version_range
"<= 6.4.8"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/07/GHSA-q2qh-cgc2-qhr3/GHSA-q2qh-cgc2-qhr3.json"