serve node module before 6.4.9 suffers from a Path Traversal vulnerability due to not handling %2e (.) and %2f (/) and allowing them in paths, which allows a malicious user to view the contents of any directory with known path.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: hackerone
Published: 2018-06-07T02:00:00Z
Updated: 2024-09-17T00:05:56.311Z
Reserved: 2017-12-28T00:00:00
Link: CVE-2018-3712
Vulnrichment
No data.
NVD
Status : Modified
Published: 2018-06-07T02:29:07.897
Modified: 2024-11-21T04:05:55.840
Link: CVE-2018-3712
Redhat
No data.