Описание
Hexo include_code has a path traversal
Hexo up to v7.1.1 was discovered to contain an arbitrary file read vulnerability.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2023-39584
- https://github.com/hexojs/hexo/issues/5250
- https://github.com/hexojs/hexo/pull/5251
- https://github.com/hexojs/hexo/commit/b5b63caee27256d71a0cee8954c22375ec885d07
- https://github.com/hexojs/hexo/blob/a3e68e7576d279db22bd7481914286104e867834/lib/plugins/tag/include_code.js#L49
- https://github.com/hexojs/hexo/blob/cefee921153ba597316457f4fedf7b87b6516917/lib/plugins/tag/include_code.ts#L50
Пакеты
Наименование
hexo
npm
Затронутые версииВерсия исправления
< 7.2.0
7.2.0
Связанные уязвимости
CVSS3: 7.5
nvd
больше 2 лет назад
Hexo up to v7.0.0 (RC2) was discovered to contain an arbitrary file read vulnerability.