Логотип exploitDog
bind:CVE-2023-38695
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-38695

Количество 2

Количество 2

nvd логотип

CVE-2023-38695

больше 2 лет назад

cypress-image-snapshot shows visual regressions in Cypress with jest-image-snapshot. Prior to version 8.0.2, it's possible for a user to pass a relative file path for the snapshot name and reach outside of the project directory into the machine running the test. This issue has been patched in version 8.0.2.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-vxjg-hchx-cc4g

больше 2 лет назад

@simonsmith/cypress-image-snapshothas fix for insecure snapshot file names

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-38695

cypress-image-snapshot shows visual regressions in Cypress with jest-image-snapshot. Prior to version 8.0.2, it's possible for a user to pass a relative file path for the snapshot name and reach outside of the project directory into the machine running the test. This issue has been patched in version 8.0.2.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-vxjg-hchx-cc4g

@simonsmith/cypress-image-snapshothas fix for insecure snapshot file names

CVSS3: 6.5
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу