Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXh3ZzQtOTNjNi0zaDQy
Directory Traversal in send
Versions 0.8.3 and earlier of send
are affected by a directory traversal vulnerability. When relying on the root option to restrict file access it may be possible for an application consumer to escape out of the restricted directory and access files in a similarly named directory.
For example, static(_dirname + '/public')
would allow access to _dirname + '/public-restricted'
.
Recommendation
Update to version 0.8.4 or later.
Permalink: https://github.com/advisories/GHSA-xwg4-93c6-3h42JSON: https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXh3ZzQtOTNjNi0zaDQy
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Low
Classification: General
Published: about 7 years ago
Updated: almost 2 years ago
Identifiers: GHSA-xwg4-93c6-3h42, CVE-2014-6394
References:
- https://nvd.nist.gov/vuln/detail/CVE-2014-6394
- https://github.com/visionmedia/send/pull/59
- https://github.com/visionmedia/send/commit/9c6ca9b2c0b880afd3ff91ce0d211213c5fa5f9a
- https://github.com/advisories/GHSA-xwg4-93c6-3h42
- https://www.npmjs.com/advisories/32
- https://bugzilla.redhat.com/show_bug.cgi?id=1146063
- https://exchange.xforce.ibmcloud.com/vulnerabilities/96727
- https://support.apple.com/HT205217
- http://lists.apple.com/archives/security-announce/2015/Sep/msg00002.html
- http://lists.fedoraproject.org/pipermail/package-announce/2014-October/139938.html
- http://lists.fedoraproject.org/pipermail/package-announce/2014-October/140020.html
- http://lists.fedoraproject.org/pipermail/package-announce/2014-September/139415.html
- http://secunia.com/advisories/62170
- http://www-01.ibm.com/support/docview.wss?uid=swg21687263
- http://www.openwall.com/lists/oss-security/2014/09/24/1
- http://www.openwall.com/lists/oss-security/2014/09/30/10
- http://www.securityfocus.com/bid/70100
Blast Radius: 0.0
Affected Packages
npm:send
Dependent packages: 2,106Dependent repositories: 4,993,661
Downloads: 163,187,086 last month
Affected Version Ranges: < 0.8.4
Fixed in: 0.8.4
All affected versions: 0.0.1, 0.0.2, 0.0.3, 0.0.4, 0.1.0, 0.1.1, 0.1.2, 0.1.3, 0.1.4, 0.2.0, 0.3.0, 0.4.0, 0.4.1, 0.4.2, 0.4.3, 0.5.0, 0.6.0, 0.7.0, 0.7.1, 0.7.2, 0.7.3, 0.7.4, 0.8.0, 0.8.1, 0.8.2, 0.8.3
All unaffected versions: 0.8.4, 0.8.5, 0.9.0, 0.9.1, 0.9.2, 0.9.3, 0.10.0, 0.10.1, 0.11.0, 0.11.1, 0.12.0, 0.12.1, 0.12.2, 0.12.3, 0.13.0, 0.13.1, 0.13.2, 0.14.0, 0.14.1, 0.14.2, 0.15.0, 0.15.1, 0.15.2, 0.15.3, 0.15.4, 0.15.5, 0.15.6, 0.16.0, 0.16.1, 0.16.2, 0.17.0, 0.17.1, 0.17.2, 0.18.0, 0.19.0, 0.19.1, 1.0.0, 1.1.0