Description
Affected versions of hostr
are vulnerable to directory traversal which allows attackers to read files outside the current directory by sending ../
in the url path for GET requests.
Recommendation
Update the hostr
package to the latest compatible version. Followings are version details:
- Affected version(s): <= 2.3.5
- Patched version(s): 2.3.6
References
Related Issues
- Prototype Pollution in lodash - CVE-2018-3721
- Cross-site Scripting in quill - CVE-2021-3163
- Prototype Pollution in async - CVE-2021-43138
- Joplin Remote Code Execution - CVE-2022-40277
- Tags:
- npm
- hostr
Anything's wrong? Let us know Last updated on September 12, 2023