Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWc0eHAtMzZjMy1mN21y
Hidden Directories Always Served in inert
Versions 1.1.1 and earlier of inert
are vulnerable to an information leakage vulnerability which causes files in hidden directories to be served, even when showHidden is false.
The inert directory handler always allows files in hidden directories to be served, even when showHidden
is false.
Recommendation
Update to version >= 1.1.1.
Permalink: https://github.com/advisories/GHSA-g4xp-36c3-f7mrJSON: https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWc0eHAtMzZjMy1mN21y
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: over 4 years ago
Updated: about 2 years ago
EPSS Percentage: 0.0017
EPSS Percentile: 0.5451
Identifiers: GHSA-g4xp-36c3-f7mr, CVE-2014-10068
References:
- https://github.com/hapijs/inert/pull/15
- https://github.com/hapijs/inert/commit/e8f99f94da4cb08e8032eda984761c3f111e3e82
- https://www.npmjs.com/advisories/14
- https://nvd.nist.gov/vuln/detail/CVE-2014-10068
- https://github.com/advisories/GHSA-g4xp-36c3-f7mr
Blast Radius: 0.0
Affected Packages
npm:inert
Dependent packages: 596Dependent repositories: 16,750
Downloads: 63,241 last month
Affected Version Ranges: < 1.1.1
Fixed in: 1.1.1
All affected versions: 1.0.0, 1.1.0
All unaffected versions: 1.1.1, 2.0.0, 2.1.0, 2.1.1, 2.1.2, 2.1.3, 2.1.4, 2.1.5, 2.1.6, 3.0.0, 3.0.1, 3.0.2, 3.1.0, 3.2.0, 3.2.1, 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.1.0, 4.2.0, 4.2.1, 5.0.0, 5.0.1, 5.1.0, 5.1.1, 5.1.2, 5.1.3