GHSA-g7j3-p357-cw8p
Dashboard / Vulnerabilities / GHSA-g7j3-p357-cw8p
Summary: Directory Traversal in f2e-server
Details: Affected versions of `f2e-server` resolve relative file paths, resulting in a directory traversal vulnerability. A malicious actor can use this vulnerability to access files outside of the intended directory root, which may result in the disclosure of private files on the vulnerable system. **Example request:** ```http GET /../../../../../../../../../../etc/passwd HTTP/1.1 host:foo ``` ## Recommendation Update to version 1.12.12 or later.
References: https://nvd.nist.gov/vuln/detail/CVE-2017-16038, https://github.com/shy2850/node-server/issues/10, https://github.com/shy2850/node-server/pull/12/files, https://github.com/advisories/GHSA-g7j3-p357-cw8p, https://github.com/shy2850/node-server, https://www.npmjs.com/advisories/346
Affected packages
Package
Name: f2e-server
Purl: pkg:npm/f2e-server
Affected ranges
Type: SEMVER
Events:
