QID 980906
QID 980906: Nodejs (npm) Security Update for simplehttpserver (GHSA-vwr2-wj63-86gr)
All versions of `simplehttpserver` are vulnerable to Path Traversal.
This vulnerability allows an attacker to access files outside the webroot since it allows symlink navigation in the URL.
## Recommendation
No fix is currently available. Do not use `simplehttpserver` in production or consider using an alternative module until a fix is made available.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-vwr2-wj63-86gr for updates pertaining to this vulnerability.
Vendor References
- GHSA-vwr2-wj63-86gr -
github.com/advisories/GHSA-vwr2-wj63-86gr
CVEs related to QID 980906
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-vwr2-wj63-86gr | simplehttpserver |
|