LOW3.1
GHSA-c3x7-gjmx-r2ff
Open Redirect in serve-static
Quick fix
GHSA-c3x7-gjmx-r2ff — serve-static: upgrade to the fixed version with the command below.
npm install serve-static@1.7.2Details
Versions of `serve-static` prior to 1.6.5 ( or 1.7.x prior to 1.7.2 ) are affected by an open redirect vulnerability on some browsers when configured to mount at the root directory.
## Proof of Concept
A link to `http://example.com//www.google.com/%2e%2e` will redirect to `//www.google.com/%2e%2e`
Some browsers will interpret this as `http://www.google.com/%2e%2e`, resulting in an external redirect.
## Recommendation
Version 1.7.x: Update to version 1.7.2 or later. Version 1.6.x: Update to version 1.6.5 or later.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2015-1164[ADVISORY]
- https://github.com/expressjs/serve-static/issues/26[WEB]
- https://bugzilla.redhat.com/show_bug.cgi?id=1181917[WEB]
- https://exchange.xforce.ibmcloud.com/vulnerabilities/99936[WEB]
- https://github.com/expressjs/serve-static[PACKAGE]
- https://snyk.io/vuln/npm:serve-static:20150113[WEB]
- https://www.npmjs.com/advisories/35[WEB]
- http://www.securityfocus.com/bid/72064[WEB]