Описание
Root Path Disclosure in send
Versions of send prior to 0.11.2 are affected by an information leakage vulnerability which may allow an attacker to enumerate paths on the server filesystem.
Recommendation
Update to version 0.11.1 or later.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2015-8859
- https://github.com/pillarjs/send/pull/70
- https://github.com/pillarjs/send/commit/98a5b89982b38e79db684177cf94730ce7fc7aed
- https://github.com/expressjs/serve-static/blob/master/HISTORY.md#181--2015-01-20
- https://web.archive.org/web/20200227192016/https://www.securityfocus.com/bid/96435
- http://www.openwall.com/lists/oss-security/2016/04/20/11
Пакеты
Наименование
send
npm
Затронутые версииВерсия исправления
< 0.11.1
0.11.1
Связанные уязвимости
CVSS3: 5.3
ubuntu
около 9 лет назад
The send package before 0.11.1 for Node.js allows attackers to obtain the root path via unspecified vectors.
CVSS3: 5.3
nvd
около 9 лет назад
The send package before 0.11.1 for Node.js allows attackers to obtain the root path via unspecified vectors.
CVSS3: 5.3
debian
около 9 лет назад
The send package before 0.11.1 for Node.js allows attackers to obtain ...