QID 984062
QID 984062: Nodejs (npm) Security Update for stattic (GHSA-w4pv-w56c-mg4v)
Versions of `stattic` before 0.3.0 are vulnerable to path traversal allowing a remote attacker to read arbitrary files with any extension from the server that users `stattic`. ## Recommendation Update to version 0.3.0 or later.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-w4pv-w56c-mg4v for updates pertaining to this vulnerability.
Vendor References
- GHSA-w4pv-w56c-mg4v -
github.com/advisories/GHSA-w4pv-w56c-mg4v
CVEs related to QID 984062
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-w4pv-w56c-mg4v | stattic |
|