Lucene search

K
osvGoogleOSV:GHSA-G4XP-36C3-F7MR
HistoryAug 31, 2020 - 10:47 p.m.

Hidden Directories Always Served in inert

2020-08-3122:47:41
Google
osv.dev
9
hidden directories
information leakage
software vulnerability
directory handler

EPSS

0.002

Percentile

54.1%

Versions 1.1.1 and earlier of inert are vulnerable to an information leakage vulnerability which causes files in hidden directories to be served, even when showHidden is false.

The inert directory handler always allows files in hidden directories to be served, even when showHidden is false.

Recommendation

Update to version >= 1.1.1.

EPSS

0.002

Percentile

54.1%

Related for OSV:GHSA-G4XP-36C3-F7MR