VDB
Sign up
HIGH

GHSA-7c9w-qmrq-ff8r

Path Traversal in http-live-simulator

Quick fix

GHSA-7c9w-qmrq-ff8r — http-live-simulator: upgrade to the fixed version with the command below.

npm install http-live-simulator@1.0.7

Details

Versions of `http-live-simulator` prior to 1.0.7 are vulnerable to Path Traversal. Due to insufficient input sanitization, attackers can access server files by using relative paths. For example: `curl --path-as-is http://localhost:8080//../../../../etc/passwd`.

## Recommendation

Upgrade to version 1.0.7

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/http-live-simulator
Introduced in: 0Fixed in: 1.0.7
Fixnpm install http-live-simulator@1.0.7

References