QID 980766
QID 980766: Nodejs (npm) Security Update for serve-here.js (GHSA-4448-rc82-fcr7)
Versions of serve-here.js prior to 1.2.0 are vulnerable to Path Traversal. The package fails to sanitize URLs, allowing attackers to access server files outside of the served folder using relative paths.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-4448-rc82-fcr7 for updates pertaining to this vulnerability.
Vendor References
- GHSA-4448-rc82-fcr7 -
github.com/advisories/GHSA-4448-rc82-fcr7
CVEs related to QID 980766
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-4448-rc82-fcr7 | serve-here.js |
|