QID 984084
QID 984084: Nodejs (npm) Security Update for restafary (GHSA-xg5r-8j97-2wrj)
Affected versions of `restafary` are susceptible to a directory traversal vulnerability when a root path is specified in the configuration. Proof of Concept ``` curl -i -s -k -X 'GET' -H 'Authorization: Basic YWRtaW46cGFzc3dvcmQ=' 'http://localhost:8000/api/v1/fs/..%2f..%2fetc/passwd' ``` ## Recommendation Update to version 1.6.1 or later.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-xg5r-8j97-2wrj for updates pertaining to this vulnerability.
Vendor References
- GHSA-xg5r-8j97-2wrj -
github.com/advisories/GHSA-xg5r-8j97-2wrj
CVEs related to QID 984084
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-xg5r-8j97-2wrj | restafary |
|