QID 984091
QID 984091: Nodejs (npm) Security Update for inert (GHSA-g4xp-36c3-f7mr)
Versions 1.1.1 and earlier of `inert` are vulnerable to an information leakage vulnerability which causes files in hidden directories to be served, even when showHidden is false. The inert directory handler always allows files in hidden directories to be served, even when `showHidden` is false. ## Recommendation Update to version >= 1.1.1.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-g4xp-36c3-f7mr for updates pertaining to this vulnerability.
Vendor References
- GHSA-g4xp-36c3-f7mr -
github.com/advisories/GHSA-g4xp-36c3-f7mr
CVEs related to QID 984091
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-g4xp-36c3-f7mr | inert |
|