MEDIUM5.3
GHSA-jgqf-hwc5-hh37
Root Path Disclosure in send
Quick fix
GHSA-jgqf-hwc5-hh37 — send: upgrade to the fixed version with the command below.
npm install send@0.11.1Details
Versions of `send` prior to 0.11.2 are affected by an information leakage vulnerability which may allow an attacker to enumerate paths on the server filesystem.
## Recommendation
Update to version 0.11.1 or later.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2015-8859[ADVISORY]
- https://github.com/pillarjs/send/pull/70[WEB]
- https://github.com/pillarjs/send/commit/98a5b89982b38e79db684177cf94730ce7fc7aed[WEB]
- https://github.com/expressjs/serve-static/blob/master/HISTORY.md#181--2015-01-20[WEB]
- https://github.com/pillarjs/send[PACKAGE]
- https://web.archive.org/web/20200227192016/https://www.securityfocus.com/bid/96435[WEB]
- http://www.openwall.com/lists/oss-security/2016/04/20/11[WEB]