QID 984048
QID 984048: Nodejs (npm) Security Update for public (GHSA-rwv8-jvff-jq28)
Versions of `public` before 0.1.3 are vulnerable to path traversal. This is due to lack of file path sanitization which could lead to any file the parent process has access to on the server to be read by malicious user. ## Recommendation Update to version 0.1.3 or later.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-rwv8-jvff-jq28 for updates pertaining to this vulnerability.
Vendor References
- GHSA-rwv8-jvff-jq28 -
github.com/advisories/GHSA-rwv8-jvff-jq28
CVEs related to QID 984048
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-rwv8-jvff-jq28 | public |
|