Lucene search

K
osvGoogleOSV:GHSA-5RC4-8QQH-VQ7F
HistoryAug 09, 2021 - 10:24 p.m.

vercel/serve allows access to restricted files if filename is URL encoded.

2021-08-0922:24:26
Google
osv.dev
12

0.001 Low

EPSS

Percentile

47.7%

serve node module suffers from Improper Handling of URL Encoding by permitting access to ignored files if a filename is URL encoded.

CPENameOperatorVersion
servelt6.5.2

0.001 Low

EPSS

Percentile

47.7%

Related for OSV:GHSA-5RC4-8QQH-VQ7F