Description
Affected versions of hostr are vulnerable to directory traversal which allows attackers to read files outside the current directory by sending ../ in the url path for GET requests.
Recommendation
Update the hostr package to the latest compatible version. Followings are version details:
- Affected version(s): <= 2.3.5
- Patched version(s): 2.3.6
References
Related Issues
- jqueryFileTree vulnerable to Directory Traversal - CVE-2017-1000170
- Directory Traversal in fbr-client - CVE-2017-16217
- Directory Traversal in node-simple-router - CVE-2017-16083
- Directory Traversal in rtcmulticonnection-client - CVE-2017-16125
- Tags:
- npm
- hostr
Anything's wrong? Let us know Last updated on September 12, 2023