QID 983423
QID 983423: Nodejs (npm) Security Update for knightjs (GHSA-3hvm-hgpw-rx4j)
All versions of `knightjs` are vulnerable to Path Traversal.
This vulnerability allows an attacker to read content of arbitrary files on the server due to lack of input validation.
## Recommendation
As there is currently no fix for this module we recommend not using this module in production environments.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-3hvm-hgpw-rx4j for updates pertaining to this vulnerability.
Vendor References
- GHSA-3hvm-hgpw-rx4j -
github.com/advisories/GHSA-3hvm-hgpw-rx4j
CVEs related to QID 983423
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-3hvm-hgpw-rx4j | knightjs |
|