HIGH
GHSA-2hw7-mxvj-m455
Path traversal in Node-RED-Dashboard
Quick fix
GHSA-2hw7-mxvj-m455 — node-red-dashboard: upgrade to the fixed version with the command below.
npm install node-red-dashboard@2.26.2Details
In Node-RED-Dashboard before 2.26.2 there is a path traversal vulnerability. It allows ui_base/js/..%2f directory traversal to read files.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2021-3223[ADVISORY]
- https://github.com/node-red/node-red-dashboard/issues/669[WEB]
- https://github.com/node-red/node-red-dashboard/commit/f48f356df966f607ba3d09c27396074b81f2ae97[WEB]
- https://github.com/node-red/node-red-dashboard/releases/tag/2.26.2[WEB]
- https://www.npmjs.com/package/node-red-dashboard[WEB]