Lucene search

K
nodejsToannc123NODEJS:1077
HistoryJul 17, 2019 - 8:57 p.m.

Path Traversal

2019-07-1720:57:43
toannc123
www.npmjs.com
7

0.001 Low

EPSS

Percentile

48.3%

Overview

All versions of http-file-server are vulnerable to Path Traversal. The package fails to sanitize URLs, allowing attackers to access server files outside of the served folder using relative paths.

Recommendation

No fix is currently available. Consider using an alternative package until a fix is made available.

References

CPENameOperatorVersion
http-file-serverge0.0.0

0.001 Low

EPSS

Percentile

48.3%