Exploit Report

Computer Security And Bug Information


CVE Title
Published Date2023-03-06T05:15Z
Modified Date2023-03-10T22:43Z
CWE TypeCWE-22
DescriptionAll versions of the package @nubosoftware/node-static; all versions of the package node-static are vulnerable to Directory Traversal due to improper file path sanitization in the startsWith() method in the servePath function.
By clicking these links you will leave this website. We do not endorse and will not be held accountable for any activity on external sites.
Reference URLhttps://github.com/cloudhead/node-static/blob/master/lib/node-static.js%23L160-L163
Reference DescriptionMISC https://github.com/cloudhead/node-static/blob/master/lib/node-static.js%23L160-L163
Reference URLhttps://gist.github.com/lirantal/c80b28e7bee148dc287339cb483e42bc
Reference DescriptionMISC https://gist.github.com/lirantal/c80b28e7bee148dc287339cb483e42bc
Reference URLhttps://security.snyk.io/vuln/SNYK-JS-NUBOSOFTWARENODESTATIC-3149927
Reference DescriptionMISC https://security.snyk.io/vuln/SNYK-JS-NUBOSOFTWARENODESTATIC-3149927
Reference URLhttps://security.snyk.io/vuln/SNYK-JS-NODESTATIC-3149928
Reference DescriptionMISC https://security.snyk.io/vuln/SNYK-JS-NODESTATIC-3149928
TagsBroken Link

This site's data is aggregated programmatically and provided "as is" without any representations or warranties, express or implied. Exploit.report is not affiliated with the The MITRE Corporation, U.S. Department of Homeland Security (DHS), Cybersecurity and Infrastructure Security Agency (CISA), or US government in any way. CVE and the CVE logo are registered trademarks of The MITRE Corporation

© 2022 Exploit.Report | Data | Contact | Privacy Policy | Articles