QID 980774
QID 980774: Nodejs (npm) Security Update for send (GHSA-xwg4-93c6-3h42)
Versions 0.8.3 and earlier of `send` are affected by a directory traversal vulnerability. When relying on the root option to restrict file access it may be possible for an application consumer to escape out of the restricted directory and access files in a similarly named directory.
For example, `static(_dirname + '/public')` would allow access to `_dirname + '/public-restricted'`.
## Recommendation
Update to version 0.8.4 or later.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-xwg4-93c6-3h42 for updates pertaining to this vulnerability.
Vendor References
- GHSA-xwg4-93c6-3h42 -
github.com/advisories/GHSA-xwg4-93c6-3h42
CVEs related to QID 980774
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-xwg4-93c6-3h42 | send |
|