Lucene search

K
osvGoogleOSV:GHSA-7C9W-QMRQ-FF8R
HistoryFeb 07, 2019 - 6:14 p.m.

Path Traversal in http-live-simulator

2019-02-0718:14:21
Google
osv.dev
6

0.004 Low

EPSS

Percentile

75.2%

Versions of http-live-simulator prior to 1.0.7 are vulnerable to Path Traversal. Due to insufficient input sanitization, attackers can access server files by using relative paths. For example: curl --path-as-is http://localhost:8080//../../../../etc/passwd.

Recommendation

Upgrade to version 1.0.7

CPENameOperatorVersion
http-live-simulatorlt1.0.7

0.004 Low

EPSS

Percentile

75.2%