QID 983753
QID 983753: Nodejs (npm) Security Update for st (GHSA-69rr-wvh9-6c4q)
Versions of `st` prior to 0.2.5 are affected by a directory traversal vulnerability. Vulnerable versions fail to properly handle URL encoded dots, which caused `%2e` to be interpreted as `.` by the filesystem, resulting the potential for an attacker to read sensitive files on the server. ## Recommendation Update to version 0.2.5 or later.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-69rr-wvh9-6c4q for updates pertaining to this vulnerability.
Vendor References
- GHSA-69rr-wvh9-6c4q -
github.com/advisories/GHSA-69rr-wvh9-6c4q
CVEs related to QID 983753
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-69rr-wvh9-6c4q | st |
|