GHSA-4rvg-955w-h68q
Dashboard / Vulnerabilities / GHSA-4rvg-955w-h68q
Summary: Path Traversal in angular-http-server
Details: Affected versions of `angular-http-server` are vulnerable to path traversal allowing a remote attacker to read files from the server that uses `angular-http-server`. ## Recommendation Update to version 1.6.0 or later. :exclamation: Note: This was originally thought to be fixed in version 1.4.3, though according to [this issue](https://github.com/ossf-cve-benchmark/ossf-cve-benchmark/issues/117#issuecomment-803872454) the vulnerability was not completely fixed until version 1.6.0.
References: https://nvd.nist.gov/vuln/detail/CVE-2018-3713, https://github.com/simonh1000/angular-http-server/pull/21, https://github.com/simonh1000/angular-http-server/commit/34d4bd0cd0f00c46db30855a8c4aabae27eb0ac8, https://hackerone.com/reports/309120, https://github.com/advisories/GHSA-4rvg-955w-h68q, https://www.npmjs.com/advisories/589
Affected packages
Package
Name: angular-http-server
Purl: pkg:npm/angular-http-server
Affected ranges
Type: SEMVER
Events:
