QID 983455
QID 983455: Nodejs (npm) Security Update for mcstatic (GHSA-cxmj-qjv6-vx9p)
A server directory traversal vulnerability was found on node module mcstatic <=0.0.20 that would allow an attack to access sensitive information in the file system by appending slashes in the URL path.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-cxmj-qjv6-vx9p for updates pertaining to this vulnerability.
Vendor References
- GHSA-cxmj-qjv6-vx9p -
github.com/advisories/GHSA-cxmj-qjv6-vx9p
CVEs related to QID 983455
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-cxmj-qjv6-vx9p | mcstatic |
|