Описание
Hidden Directories Always Served in inert
Versions 1.1.1 and earlier of inert are vulnerable to an information leakage vulnerability which causes files in hidden directories to be served, even when showHidden is false.
The inert directory handler always allows files in hidden directories to be served, even when showHidden is false.
Recommendation
Update to version >= 1.1.1.
Пакеты
Наименование
inert
npm
Затронутые версииВерсия исправления
< 1.1.1
1.1.1
Связанные уязвимости
CVSS3: 7.5
nvd
больше 7 лет назад
The inert directory handler in inert node module before 1.1.1 always allows files in hidden directories to be served, even when `showHidden` is false.