QID 983123
QID 983123: Nodejs (npm) Security Update for statics-server (GHSA-j27j-4w6m-8fc4)
All versions of `statics-server` are vulnerable to Path Traversal. The package fails to limit access to files outside of the served folder through symlinks.
## Recommendation
No fix is currently available. Do not use `statics-server` in production or consider using an alternative module until a fix is made available.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-j27j-4w6m-8fc4 for updates pertaining to this vulnerability.
Vendor References
- GHSA-j27j-4w6m-8fc4 -
github.com/advisories/GHSA-j27j-4w6m-8fc4
CVEs related to QID 983123
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-j27j-4w6m-8fc4 | statics-server |
|