Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:25958
HistoryJul 27, 2020 - 4:15 a.m.

Directory Traversal

2020-07-2704:15:41
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
3
fast-http
directory traversal
fs.readfile function
index.js
web root
arbitrary files security vulnerability

EPSS

0.006

Percentile

79.3%

fast-http is vulnerable to directory traversal. Lack of path sanitization in the fs.readfile function in index.js allows an attacker to access arbitrary files outside of the web root.

EPSS

0.006

Percentile

79.3%

Related for VERACODE:25958