Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLW04ZnctNTM0di14bTg1
Cross-Site Scripting (XSS) in cloudcmd
Versions of cloudcmd
before 9.1.6 are vulnerable to cross-site scripting (XSS) when listing files in a directory. The attacker must control the name of a file for this vulnerability to be exploitable.
Recommendation
Update to version 9.1.6 or later.
Permalink: https://github.com/advisories/GHSA-m8fw-534v-xm85JSON: https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLW04ZnctNTM0di14bTg1
Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: over 5 years ago
Updated: almost 2 years ago
Identifiers: GHSA-m8fw-534v-xm85
References:
- https://github.com/coderaiser/cloudcmd/commit/23f4d4702cd3d473977285f26ea2ae7206b45f38
- https://hackerone.com/reports/341044
- https://hackerone.com/reports/341044)
- https://www.npmjs.com/advisories/642
- https://github.com/advisories/GHSA-m8fw-534v-xm85
Blast Radius: 0.0
Affected Packages
npm:cloudcmd
Dependent packages: 5Dependent repositories: 27
Downloads: 2,828 last month
Affected Version Ranges: < 9.1.6
Fixed in: 9.1.6
All affected versions: 0.1.0, 0.1.1, 0.1.2, 0.1.3, 0.1.4, 0.1.5, 0.1.6, 0.1.7, 0.1.8, 0.1.9, 0.2.0, 0.3.0, 0.4.0, 0.5.0, 0.6.0, 0.7.0, 0.8.0, 0.8.1, 0.8.2, 0.8.3, 0.8.4, 0.9.0, 0.9.1, 0.9.2, 1.0.0, 1.0.1, 1.1.0, 1.1.1, 1.2.0, 1.3.0, 1.3.1, 1.3.2, 1.4.0, 1.4.1, 1.5.0, 1.5.1, 2.0.0, 2.1.0, 2.2.0, 2.2.1, 2.3.0, 2.3.1, 2.4.0, 2.4.1, 2.4.2, 2.5.0, 2.5.1, 2.6.0, 2.7.0, 2.7.1, 2.8.0, 2.9.0, 2.9.1, 2.9.2, 2.9.3, 3.0.0, 3.0.1, 3.0.2, 3.0.3, 3.0.4, 3.1.0, 3.1.1, 3.1.2, 3.1.3, 3.1.4, 3.2.0, 3.3.0, 3.4.0, 3.5.0, 3.6.0, 3.7.0, 3.7.1, 3.7.2, 3.8.0, 3.8.1, 4.0.0, 4.1.0, 4.1.1, 4.1.2, 4.2.0, 4.3.0, 4.3.1, 4.3.2, 4.3.3, 4.3.4, 4.3.5, 4.4.0, 4.5.0, 4.5.1, 4.5.2, 4.5.3, 4.5.4, 4.5.5, 4.5.6, 4.5.7, 4.6.0, 4.7.0, 4.7.1, 4.7.2, 4.7.3, 4.7.4, 4.7.5, 4.7.6, 4.7.7, 5.0.0, 5.0.1, 5.0.2, 5.0.3, 5.0.4, 5.0.5, 5.0.6, 5.0.7, 5.0.8, 5.0.9, 5.0.10, 5.0.11, 5.0.12, 5.0.13, 5.0.14, 5.0.15, 5.1.0, 5.1.1, 5.1.2, 5.1.3, 5.1.4, 5.1.5, 5.2.0, 5.2.1, 5.2.2, 5.2.3, 5.3.0, 5.3.1, 5.3.2, 5.4.0, 5.4.1, 5.4.2, 5.4.3, 5.5.0, 5.5.1, 5.6.0, 5.6.1, 5.6.2, 5.7.0, 5.7.1, 5.7.2, 5.7.3, 5.7.4, 5.7.5, 5.7.6, 5.8.0, 5.9.0, 5.9.1, 5.10.0, 5.10.1, 5.10.2, 5.11.0, 5.11.1, 5.12.0, 5.12.1, 5.12.2, 5.12.3, 5.12.4, 5.13.0, 6.0.0, 6.0.1, 6.0.2, 6.0.3, 6.1.0, 6.2.0, 6.2.1, 6.2.2, 6.3.0, 6.3.1, 6.4.0, 6.5.0, 6.5.1, 6.5.2, 6.5.3, 6.5.4, 6.5.5, 6.5.6, 6.6.0, 6.6.1, 6.6.2, 6.6.3, 6.7.0, 6.8.0, 6.8.1, 6.9.0, 6.9.1, 6.9.2, 6.9.3, 6.10.0, 6.10.1, 6.11.0, 6.12.0, 6.13.0, 6.14.0, 6.14.1, 6.14.2, 6.14.3, 6.14.4, 6.15.0, 6.15.1, 6.15.2, 6.15.3, 6.15.4, 6.15.5, 7.0.0, 7.0.1, 7.0.2, 7.1.0, 7.1.1, 7.2.0, 7.2.1, 7.2.2, 7.3.0, 7.3.1, 7.3.2, 7.4.0, 7.5.0, 7.5.1, 7.5.2, 7.6.0, 7.7.0, 7.7.1, 7.7.2, 7.7.3, 7.8.0, 7.9.0, 8.0.0, 8.0.1, 8.0.2, 8.0.3, 8.0.4, 8.0.5, 8.1.0, 8.1.1, 8.1.2, 8.1.3, 8.2.0, 8.2.1, 8.2.2, 8.3.0, 8.4.0, 8.4.1, 8.5.0, 8.5.1, 8.5.2, 9.0.0, 9.1.0, 9.1.1, 9.1.2, 9.1.3, 9.1.4, 9.1.5
All unaffected versions: 9.1.6, 9.2.0, 9.3.0, 9.3.1, 9.3.2, 9.4.0, 9.5.0, 9.6.0, 10.0.0, 10.0.1, 10.0.2, 10.0.3, 10.1.0, 10.1.1, 10.1.2, 10.2.0, 10.2.1, 10.2.2, 10.2.3, 10.3.0, 10.3.1, 10.3.2, 10.4.0, 10.4.1, 10.5.0, 10.5.1, 10.5.2, 10.5.3, 10.6.0, 10.7.0, 10.8.0, 10.8.1, 10.8.2, 11.0.0, 11.1.0, 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.3.0, 11.3.1, 11.4.0, 11.4.1, 11.5.0, 11.5.1, 11.5.2, 11.5.3, 11.5.4, 11.6.0, 11.7.0, 11.7.1, 11.8.0, 11.8.1, 11.8.2, 11.8.3, 11.8.4, 11.8.5, 11.8.6, 12.0.0, 12.0.1, 12.0.2, 12.1.0, 12.2.0, 12.3.0, 12.3.1, 12.3.2, 12.4.0, 12.5.0, 12.6.0, 12.6.1, 12.6.2, 12.6.3, 13.0.0, 13.0.1, 13.1.0, 13.2.0, 13.2.1, 13.3.0, 13.4.0, 13.4.1, 13.4.2, 14.0.0, 14.0.1, 14.0.2, 14.1.0, 14.1.1, 14.1.2, 14.2.0, 14.2.1, 14.3.0, 14.3.1, 14.3.2, 14.3.3, 14.3.4, 14.3.5, 14.3.6, 14.3.7, 14.3.8, 14.3.9, 14.3.10, 14.4.0, 14.5.0, 14.5.1, 14.6.0, 14.7.0, 14.7.1, 14.7.2, 14.8.0, 14.9.0, 14.9.1, 14.9.2, 14.9.3, 15.0.0, 15.0.1, 15.0.2, 15.0.3, 15.0.4, 15.1.0, 15.2.0, 15.3.0, 15.3.1, 15.3.2, 15.3.3, 15.3.4, 15.4.0, 15.4.1, 15.4.2, 15.4.3, 15.4.4, 15.5.0, 15.5.1, 15.5.2, 15.6.0, 15.7.0, 15.7.1, 15.8.0, 15.8.1, 15.9.0, 15.9.1, 15.9.2, 15.9.3, 15.9.4, 15.9.5, 15.9.6, 15.9.7, 15.9.8, 15.9.9, 15.9.10, 15.9.11, 15.9.12, 15.9.13, 15.9.14, 15.9.15, 16.0.0, 16.0.1, 16.1.0, 16.1.1, 16.2.0, 16.3.0, 16.3.1, 16.4.0, 16.4.1, 16.5.0, 16.6.0, 16.6.1, 16.7.0, 16.8.0, 16.9.0, 16.9.1, 16.10.0, 16.11.0, 16.12.0, 16.13.0, 16.13.1, 16.14.0, 16.14.1, 16.15.0, 16.16.0, 16.16.1, 16.16.2, 16.16.3, 16.17.0, 16.17.1, 16.17.2, 16.17.3, 16.17.4, 16.17.5, 16.17.6, 16.17.7, 16.17.8, 16.17.9, 16.18.0, 17.0.0, 17.0.1, 17.0.2, 17.0.3, 17.0.5, 17.0.6, 17.0.7, 17.1.0, 17.1.1, 17.1.2, 17.1.3, 17.1.4, 17.1.5, 17.1.6, 17.2.0, 17.2.1, 17.3.0, 17.3.1, 17.3.2, 17.3.3, 17.4.0, 17.4.1, 17.4.2, 17.4.3, 17.4.4, 18.0.0, 18.0.1, 18.0.2, 18.1.0, 18.2.0, 18.2.1, 18.3.0, 18.4.0