Lucene search

K
nodejsBl4deNODEJS:571
HistoryApr 20, 2018 - 9:43 p.m.

Path Traversal

2018-04-2021:43:09
bl4de
www.npmjs.com
18

0.004 Low

EPSS

Percentile

75.2%

Overview

Versions of public before 0.1.3 are vulnerable to path traversal. This is due to lack of file path sanitization which could lead to any file the parent process has access to on the server to be read by malicious user.

Recommendation

Update to version 0.1.3 or later.

References

CPENameOperatorVersion
publicle0.1.2

0.004 Low

EPSS

Percentile

75.2%