MEDIUM6.5
GHSA-4rvg-955w-h68q
Path Traversal in angular-http-server
Quick fix
GHSA-4rvg-955w-h68q — angular-http-server: upgrade to the fixed version with the command below.
npm install angular-http-server@1.6.0Details
Affected versions of `angular-http-server` are vulnerable to path traversal allowing a remote attacker to read files from the server that uses `angular-http-server`.
## Recommendation
Update to version 1.6.0 or later.
:exclamation: Note: This was originally thought to be fixed in version 1.4.3, though according to [this issue](https://github.com/ossf-cve-benchmark/ossf-cve-benchmark/issues/117#issuecomment-803872454) the vulnerability was not completely fixed until version 1.6.0.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2018-3713[ADVISORY]
- https://github.com/simonh1000/angular-http-server/pull/21[WEB]
- https://github.com/simonh1000/angular-http-server/commit/34d4bd0cd0f00c46db30855a8c4aabae27eb0ac8[WEB]
- https://hackerone.com/reports/309120[WEB]
- https://github.com/advisories/GHSA-4rvg-955w-h68q[ADVISORY]
- https://www.npmjs.com/advisories/589[WEB]