PT-2018-16155 · Npm+2 · Public+2

Bl4De

+1

·

Published

2018-06-07

·

Updated

2023-01-30

·

CVE-2018-3731

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions public versions prior to 0.1.3
Description The issue arises from a lack of validation of the filePath, allowing a malicious user to read the content of any file with a known path due to a Path Traversal vulnerability. This is caused by insufficient file path sanitization, which could lead to any file the parent process has access to on the server being read by a malicious user.
Recommendations Update to version 0.1.3 or later. As a temporary workaround, consider restricting access to sensitive files until the issue is resolved.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2018-3731
GHSA-RWV8-JVFF-JQ28

Affected Products

Public
Public Node Module
Public.Js