Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXJ3djgtanZmZi1qcTI4

Path Traversal in public

Versions of public before 0.1.3 are vulnerable to path traversal. This is due to lack of file path sanitization which could lead to any file the parent process has access to on the server to be read by malicious user.

Recommendation

Update to version 0.1.3 or later.

Permalink: https://github.com/advisories/GHSA-rwv8-jvff-jq28
JSON: https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXJ3djgtanZmZi1qcTI4
Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: almost 6 years ago
Updated: over 1 year ago


CVSS Score: 7.5
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Identifiers: GHSA-rwv8-jvff-jq28, CVE-2018-3731
References: Repository: https://github.com/tnantoka/public
Blast Radius: 14.0

Affected Packages

npm:public
Dependent packages: 14
Dependent repositories: 73
Downloads: 12,326 last month
Affected Version Ranges: <= 0.1.2
Fixed in: 0.1.3
All affected versions: 0.1.0, 0.1.1, 0.1.2
All unaffected versions: 0.1.3, 0.1.4, 0.1.5