Description
All versions of package lite-dev-server are vulnerable to Directory Traversal due to missing input sanitization and sandboxes being employed to the req.url user input that is passed to the server code.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-7708 | All versions of package lite-dev-server are vulnerable to Directory Traversal due to missing input sanitization and sandboxes being employed to the req.url user input that is passed to the server code. |
Github GHSA |
GHSA-pppv-ch8p-rp2w | lite-dev-server vulnerable to Directory Traversal |
References
History
Wed, 16 Apr 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: snyk
Published:
Updated: 2025-04-16T18:32:59.442Z
Reserved: 2022-02-24T00:00:00.000Z
Link: CVE-2022-25895
Updated: 2024-08-03T04:49:44.151Z
Status : Modified
Published: 2022-12-21T05:15:11.313
Modified: 2025-04-16T19:15:45.103
Link: CVE-2022-25895
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA