Lucene search

K
githubGitHub Advisory DatabaseGHSA-VWR2-WJ63-86GR
HistoryDec 06, 2018 - 3:49 p.m.

Path Traversal in simplehttpserver

2018-12-0615:49:10
CWE-22
GitHub Advisory Database
github.com
56

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

EPSS

0.001

Percentile

40.6%

All versions of simplehttpserver are vulnerable to Path Traversal.

This vulnerability allows an attacker to access files outside the webroot since it allows symlink navigation in the URL.

Recommendation

No fix is currently available. Do not use simplehttpserver in production or consider using an alternative module until a fix is made available.

Affected configurations

Vulners
Node
simplehttpserver_projectsimplehttpserverRange0.3.0node.js
VendorProductVersionCPE
simplehttpserver_projectsimplehttpserver*cpe:2.3:a:simplehttpserver_project:simplehttpserver:*:*:*:*:*:node.js:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

EPSS

0.001

Percentile

40.6%