QID 982889
QID 982889: Nodejs (npm) Security Update for angular-http-server (GHSA-4rvg-955w-h68q)
Affected versions of `angular-http-server` are vulnerable to path traversal allowing a remote attacker to read files from the server that uses `angular-http-server`.
## Recommendation
Update to version 1.6.0 or later.
:exclamation: Note: This was originally thought to be fixed in version 1.4.3, though according to [this issue](https://github.com/ossf-cve-benchmark/ossf-cve-benchmark/issues/117#issuecomment-803872454) the vulnerability was not completely fixed until version 1.6.0.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-4rvg-955w-h68q for updates pertaining to this vulnerability.
Vendor References
- GHSA-4rvg-955w-h68q -
github.com/advisories/GHSA-4rvg-955w-h68q
CVEs related to QID 982889
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-4rvg-955w-h68q | angular-http-server |
|