MEDIUM5.4
GHSA-rch9-xh7r-mqgw
Cross-Site Scripting in connect
Quick fix
GHSA-rch9-xh7r-mqgw — connect: upgrade to the fixed version with the command below.
npm install connect@2.14.0Details
connect node module before 2.14.0 suffers from a Cross-Site Scripting (XSS) vulnerability due to a lack of validation of file in directory.js middleware.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2018-3717[ADVISORY]
- https://github.com/JacksonTian/anywhere/issues/33#issuecomment-366527448[WEB]
- https://github.com/senchalabs/connect/commit/6d5dd30075d2bc4ee97afdbbe3d9d98d8d52d74b[WEB]
- https://hackerone.com/reports/309394[WEB]
- https://hackerone.com/reports/309641[WEB]
- https://github.com/advisories/GHSA-rch9-xh7r-mqgw[ADVISORY]
- https://www.npmjs.com/advisories/584[WEB]
- https://www.npmjs.com/advisories/595[WEB]