LOW
GHSA-xwg4-93c6-3h42
Directory Traversal in send
Quick fix
GHSA-xwg4-93c6-3h42 — send: upgrade to the fixed version with the command below.
npm install send@0.8.4Details
Versions 0.8.3 and earlier of `send` are affected by a directory traversal vulnerability. When relying on the root option to restrict file access it may be possible for an application consumer to escape out of the restricted directory and access files in a similarly named directory.
For example, `static(_dirname + '/public')` would allow access to `_dirname + '/public-restricted'`.
## Recommendation
Update to version 0.8.4 or later.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2014-6394[ADVISORY]
- https://github.com/visionmedia/send/pull/59[WEB]
- https://github.com/visionmedia/send/commit/9c6ca9b2c0b880afd3ff91ce0d211213c5fa5f9a[WEB]
- https://bugzilla.redhat.com/show_bug.cgi?id=1146063[WEB]
- https://exchange.xforce.ibmcloud.com/vulnerabilities/96727[WEB]
- https://github.com/advisories/GHSA-xwg4-93c6-3h42[ADVISORY]
- https://github.com/visionmedia/send[PACKAGE]
- https://support.apple.com/HT205217[WEB]
- https://www.npmjs.com/advisories/32[WEB]
- http://lists.apple.com/archives/security-announce/2015/Sep/msg00002.html[WEB]
- http://lists.fedoraproject.org/pipermail/package-announce/2014-October/139938.html[WEB]
- http://lists.fedoraproject.org/pipermail/package-announce/2014-October/140020.html[WEB]
- http://lists.fedoraproject.org/pipermail/package-announce/2014-September/139415.html[WEB]
- http://secunia.com/advisories/62170[WEB]
- http://www-01.ibm.com/support/docview.wss?uid=swg21687263[WEB]
- http://www.openwall.com/lists/oss-security/2014/09/24/1[WEB]
- http://www.openwall.com/lists/oss-security/2014/09/30/10[WEB]
- http://www.securityfocus.com/bid/70100[WEB]