QID 984079
QID 984079: Nodejs (npm) Security Update for hekto (GHSA-x26f-26qw-hhhx)
Versions of `hekto` before 0.2.3 are vulnerable to path traversal. This allows a remote attacker to read content of arbitrary files. ## Recommendation Update to version 0.2.3 or later.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-x26f-26qw-hhhx for updates pertaining to this vulnerability.
Vendor References
- GHSA-x26f-26qw-hhhx -
github.com/advisories/GHSA-x26f-26qw-hhhx
CVEs related to QID 984079
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-x26f-26qw-hhhx | hekto |
|