PT-2018-16155 · Npm+2 · Public+2

·

CVE-2018-3731

·

Published

2018-06-07

·

Updated

2023-01-30

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions public versions prior to 0.1.3
Description The issue arises from a lack of validation of the filePath, allowing a malicious user to read the content of any file with a known path due to a Path Traversal vulnerability. This is caused by insufficient file path sanitization, which could lead to any file the parent process has access to on the server being read by a malicious user.
Recommendations Update to version 0.1.3 or later. As a temporary workaround, consider restricting access to sensitive files until the issue is resolved.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-3731
GHSA-RWV8-JVFF-JQ28

Affected Products

Public
Public Node Module
Public.Js