Description
A server directory traversal vulnerability was found on node module mcstatic <=0.0.20 that would allow an attack to access sensitive information in the file system by appending slashes in the URL path.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 0.0.20
References
Related Issues
- Stimulsoft Dashboard.JS directory traversal vulnerability - CVE-2024-24398
- Path Traversal in mcstatic - CVE-2018-3730
- Directory Traversal vulnerability in serve-lite - CVE-2022-21192
- React Native Document Picker Directory Traversal vulnerability - CVE-2024-25466
You might also like:
- Tags:
- npm
- mcstatic
Anything's wrong? Let us know Last updated on September 12, 2023


