Описание
Path Traversal in hekto
Versions of hekto before 0.2.3 are vulnerable to path traversal. This allows a remote attacker to read content of arbitrary files.
Recommendation
Update to version 0.2.3 or later.
Пакеты
Наименование
hekto
npm
Затронутые версииВерсия исправления
< 0.2.3
0.2.3
Связанные уязвимости
CVSS3: 7.5
nvd
больше 7 лет назад
hekto node module suffers from a Path Traversal vulnerability due to lack of validation of file, which allows a malicious user to read content of any file with known path.