Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 2

Количество 2

nvd логотип

CVE-2020-5284

больше 6 лет назад

Next.js versions before 9.3.2 have a directory traversal vulnerability. Attackers could craft special requests to access files in the dist directory (.next). This does not affect files outside of the dist directory (.next). In general, the dist directory only holds build assets unless your application intentionally stores other assets under this directory. This issue is fixed in version 9.3.2.

CVSS3: 4.4
EPSS: Средний
github логотип

GHSA-fq77-7p7r-83rj

больше 6 лет назад

Directory Traversal in Next.js

CVSS3: 4.4
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-5284

Next.js versions before 9.3.2 have a directory traversal vulnerability. Attackers could craft special requests to access files in the dist directory (.next). This does not affect files outside of the dist directory (.next). In general, the dist directory only holds build assets unless your application intentionally stores other assets under this directory. This issue is fixed in version 9.3.2.

CVSS3: 4.4
43%
Средний
больше 6 лет назад
github логотип
GHSA-fq77-7p7r-83rj

Directory Traversal in Next.js

CVSS3: 4.4
43%
Средний
больше 6 лет назад

Уязвимостей на страницу