Description
A path traversal vulnerability was found in module static-resource-server 1.7.2 that allows unauthorized read access to any file on the server by appending slashes in the URL.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-0217 | A path traversal vulnerability was found in module static-resource-server 1.7.2 that allows unauthorized read access to any file on the server by appending slashes in the URL. |
Github GHSA |
GHSA-45j8-pm75-5v8x | Path Traversal in simplehttpserver |
References
| Link | Providers |
|---|---|
| https://hackerone.com/reports/432600 |
|
History
No history.
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2024-08-05T10:24:32.903Z
Reserved: 2018-09-04T00:00:00.000Z
Link: CVE-2018-16493
No data.
Status : Modified
Published: 2019-02-01T18:29:01.160
Modified: 2024-11-21T03:52:51.773
Link: CVE-2018-16493
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA