VDB
Sign up
MEDIUM6.5

GHSA-4rvg-955w-h68q

Path Traversal in angular-http-server

Quick fix

GHSA-4rvg-955w-h68q — angular-http-server: upgrade to the fixed version with the command below.

npm install angular-http-server@1.6.0

Details

Affected versions of `angular-http-server` are vulnerable to path traversal allowing a remote attacker to read files from the server that uses `angular-http-server`.

## Recommendation

Update to version 1.6.0 or later.

:exclamation: Note: This was originally thought to be fixed in version 1.4.3, though according to [this issue](https://github.com/ossf-cve-benchmark/ossf-cve-benchmark/issues/117#issuecomment-803872454) the vulnerability was not completely fixed until version 1.6.0.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/angular-http-server
Introduced in: 0Fixed in: 1.6.0
Fixnpm install angular-http-server@1.6.0

References