Description
All versions of the package static-server are vulnerable to Directory Traversal due to improper input sanitization passed via the validPath function of server.js.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-2815 | static-server Path Traversal vulnerability |
Github GHSA |
GHSA-v834-rhv4-65m3 | static-server Path Traversal vulnerability |
References
History
Mon, 23 Sep 2024 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: snyk
Published:
Updated: 2024-09-23T13:30:21.983Z
Reserved: 2023-02-20T10:28:48.929Z
Link: CVE-2023-26152
Updated: 2024-08-02T11:39:06.705Z
Status : Modified
Published: 2023-10-03T05:15:50.580
Modified: 2024-11-21T07:50:53.313
Link: CVE-2023-26152
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA