Description
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.2.7, when using serveStatic with deno, it is possible to traverse the directory where `main.ts` is located. This can result in retrieval of unexpected files. Version 4.2.7 contains a patch for the issue.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-1083 | Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.2.7, when using serveStatic with deno, it is possible to traverse the directory where `main.ts` is located. This can result in retrieval of unexpected files. Version 4.2.7 contains a patch for the issue. |
Github GHSA |
GHSA-3mpf-rcc7-5347 | Hono vulnerable to Restricted Directory Traversal in serveStatic with deno |
References
History
No history.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-02T02:20:35.658Z
Reserved: 2024-04-19T14:07:11.229Z
Link: CVE-2024-32869
Updated: 2024-04-25T18:49:04.654Z
Status : Analyzed
Published: 2024-04-23T21:15:48.623
Modified: 2025-09-17T20:34:12.597
Link: CVE-2024-32869
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA