QID 983151
QID 983151: Nodejs (npm) Security Update for m-server (GHSA-899g-6q6w-7v94)
Path Traversal vulnerability in module m-server <1.4.1 allows malicious user to access unauthorized content of any file in the directory tree e.g. /etc/passwd by appending slashes to the URL request.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-899g-6q6w-7v94 for updates pertaining to this vulnerability.
Vendor References
- GHSA-899g-6q6w-7v94 -
github.com/advisories/GHSA-899g-6q6w-7v94
CVEs related to QID 983151
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-899g-6q6w-7v94 | m-server |
|