All versions of package easy-static-server are vulnerable to Directory Traversal due to missing input sanitization and sandboxes being employed to the req.url user input that is passed to the server code.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: snyk

Published: 2022-12-21T01:21:43.830108Z

Updated: 2024-09-17T02:27:11.340Z

Reserved: 2022-02-24T00:00:00

Link: CVE-2022-25931

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-12-20T05:15:11.587

Modified: 2022-12-29T18:45:08.617

Link: CVE-2022-25931

cve-icon Redhat

No data.