QID 980838
QID 980838: Nodejs (npm) Security Update for rendertron (GHSA-vqmr-957g-r7w3)
Installed packages are exposed by node_modules in Rendertron 1.0.0, allowing remote attackers to read absolute paths on the server by examining the "_where" attribute of package.json files.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-vqmr-957g-r7w3 for updates pertaining to this vulnerability.
Vendor References
- GHSA-vqmr-957g-r7w3 -
github.com/advisories/GHSA-vqmr-957g-r7w3
CVEs related to QID 980838
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-vqmr-957g-r7w3 | rendertron |
|