QID 980792
QID 980792: Nodejs (npm) Security Update for serve (GHSA-xg75-3277-gvvj)
Versions of `serve` before 7.1.3 are vulnerable to Directory Traversal. File paths are not sanitized leading to unauthorized access of system files.
## Recommendation
Upgrade to version 7.1.3 or later
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-xg75-3277-gvvj for updates pertaining to this vulnerability.
Vendor References
- GHSA-xg75-3277-gvvj -
github.com/advisories/GHSA-xg75-3277-gvvj
CVEs related to QID 980792
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-xg75-3277-gvvj | serve |
|