QID 982764
QID 982764: Nodejs (npm) Security Update for node-red-contrib-huemagic (GHSA-frpw-jrwx-hcfv)
node-red-contrib-huemagic 3.0.0 is affected by hue/assets/..%2F Directory Traversal.in the res.sendFile API, used in file hue-magic.js, to fetch an arbitrary file.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-frpw-jrwx-hcfv for updates pertaining to this vulnerability.
Vendor References
- GHSA-frpw-jrwx-hcfv -
github.com/advisories/GHSA-frpw-jrwx-hcfv
CVEs related to QID 982764
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-frpw-jrwx-hcfv | node-red-contrib-huemagic |
|