MEDIUM5.3
GHSA-vwr2-wj63-86gr
Path Traversal in simplehttpserver
Details
All versions of `simplehttpserver` are vulnerable to Path Traversal.
This vulnerability allows an attacker to access files outside the webroot since it allows symlink navigation in the URL.
## Recommendation
No fix is currently available. Do not use `simplehttpserver` in production or consider using an alternative module until a fix is made available.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/simplehttpserver
Introduced in:
0No fixed version published yet for simplehttpserver (npm). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2018-16478[ADVISORY]
- https://hackerone.com/reports/403703[WEB]
- https://github.com/advisories/GHSA-vwr2-wj63-86gr[ADVISORY]
- https://github.com/nodejs/security-wg/blob/master/vuln/npm/484.json[WEB]
- https://github.com/tikonen/blog/tree/master/simplehttpserver[PACKAGE]
- https://www.npmjs.com/advisories/744[WEB]