PT-2018-16155 · Npm+2 · Public+2

Bl4De

+1

·

Publicado

2018-06-07

·

Atualizado

2023-01-30

·

CVE-2018-3731

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions public versions prior to 0.1.3
Description The issue arises from a lack of validation of the filePath, allowing a malicious user to read the content of any file with a known path due to a Path Traversal vulnerability. This is caused by insufficient file path sanitization, which could lead to any file the parent process has access to on the server being read by a malicious user.
Recommendations Update to version 0.1.3 or later. As a temporary workaround, consider restricting access to sensitive files until the issue is resolved.

Exploit

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-3731
GHSA-RWV8-JVFF-JQ28

Produtos afetados

Public
Public Node Module
Public.Js