Описание
Path Traversal in angular-http-server
Affected versions of angular-http-server are vulnerable to path traversal allowing a remote attacker to read files from the server that uses angular-http-server.
Recommendation
Update to version 1.6.0 or later.
:exclamation: Note: This was originally thought to be fixed in version 1.4.3, though according to this issue the vulnerability was not completely fixed until version 1.6.0.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2018-3713
- https://github.com/simonh1000/angular-http-server/pull/21
- https://github.com/simonh1000/angular-http-server/commit/34d4bd0cd0f00c46db30855a8c4aabae27eb0ac8
- https://hackerone.com/reports/309120
- https://github.com/advisories/GHSA-4rvg-955w-h68q
- https://www.npmjs.com/advisories/589
Пакеты
Наименование
angular-http-server
npm
Затронутые версииВерсия исправления
< 1.6.0
1.6.0
Связанные уязвимости
CVSS3: 6.5
nvd
больше 7 лет назад
angular-http-server node module suffers from a Path Traversal vulnerability due to lack of validation of possibleFilename, which allows a malicious user to read content of any file with known path.