PT-2019-20025 · Node.Js · Gun

Publicado

2019-06-05

·

Atualizado

2019-06-05

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
Name of the Vulnerable Software and Affected Versions GUN versions prior to 0.2019.416
Description A serious issue was found in the static file server module included with GUN, where using curl --path-as-is allowed reads on any parent directory or files. This issue did not affect requests made via a browser or curl without the --path-as-is option. Most NodeJS users who use the default setup are affected. The issue is serious and could lead to the leakage of environment variables and AWS keys if not addressed.
Recommendations For versions prior to 0.2019.416, upgrade to version 0.2019.416 or higher to fix the issue. As a temporary workaround, consider avoiding the use of curl --path-as-is until the upgrade is applied. If you have custom NodeJS code, review it to ensure you are not using a vulnerable setup, such as require('http').createServer(Gun.serve( dirname)), and adjust accordingly.

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

GHSA-886V-MM6P-4M66

Produtos afetados

Gun