Описание
Path Traversal in mcstatic
All versions of mcstatic are vulnerable to path traversal.
Recommendation
No fix is currently available for this vulnerability. It is our recommendation to not install or use this module at this time.
Пакеты
Наименование
mcstatic
npm
Затронутые версииВерсия исправления
<= 0.0.20
Отсутствует
Связанные уязвимости
CVSS3: 7.5
nvd
больше 7 лет назад
mcstatic node module suffers from a Path Traversal vulnerability due to lack of validation of filePath, which allows a malicious user to read content of any file with known path.