Description
A server directory traversal vulnerability was found on node module mcstatic <=0.0.20 that would allow an attack to access sensitive information in the file system by appending slashes in the URL path.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-0280 | A server directory traversal vulnerability was found on node module mcstatic <=0.0.20 that would allow an attack to access sensitive information in the file system by appending slashes in the URL path. |
Github GHSA |
GHSA-cxmj-qjv6-vx9p | mcstatic directory traversal vulnerability |
References
| Link | Providers |
|---|---|
| https://hackerone.com/reports/330285 |
|
History
No history.
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2024-08-05T10:24:32.435Z
Reserved: 2018-09-04T00:00:00.000Z
Link: CVE-2018-16482
No data.
Status : Modified
Published: 2019-02-01T18:29:00.707
Modified: 2026-06-17T01:44:22.323
Link: CVE-2018-16482
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
EUVD
Github GHSA