Lucene search

K
osvGoogleOSV:GHSA-2MP5-M968-GWR2
HistoryJul 16, 2019 - 12:41 a.m.

Path Traversal in http-file-server

2019-07-1600:41:34
Google
osv.dev
6

0.001 Low

EPSS

Percentile

48.3%

All versions of http-file-server are vulnerable to Path Traversal. The package fails to sanitize URLs, allowing attackers to access server files outside of the served folder using relative paths.

Recommendation

No fix is currently available. Consider using an alternative package until a fix is made available.

0.001 Low

EPSS

Percentile

48.3%