GHSA-5w8q-x7hc-jhp6
Dashboard / Vulnerabilities / GHSA-5w8q-x7hc-jhp6
Summary: Directory Traversal in node-simple-router
Details: Affected versions of `node-simple-router` resolve relative file paths, resulting in a directory traversal vulnerability. A malicious actor can use this vulnerability to access files outside of the intended directory root, which may result in the disclosure of private files on the vulnerable system. **Example request:** ```http GET /../../../../../../../../../../etc/passwd HTTP/1.1 host:foo ``` ## Recommendation Update to v0.10.1 or later.
References: https://nvd.nist.gov/vuln/detail/CVE-2017-16083, https://github.com/sandy98/node-simple-router/commit/dfdd52e2e80607af433097d940b3834fd96df488, https://github.com/JacksonGL/NPM-Vuln-PoC/tree/master/directory-traversal/node-simple-router, https://github.com/advisories/GHSA-5w8q-x7hc-jhp6, https://www.npmjs.com/advisories/352
Affected packages
Package
Name: node-simple-router
Purl: pkg:npm/node-simple-router
Affected ranges
Type: SEMVER
Events:
