Vulnerabilities/

Unauthorized File Access in atompm

Severity:
High

Description

Versions of atompm prior to 0.8.2 are vulnerable to Unauthorized File Access. The package fails to sanitize relative paths in the URL for file downloads, allowing attackers to download arbitrary files from the system.

Recommendation

Update the atompm package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
atompm
Anything's wrong? Let us know Last updated on January 09, 2023

This issue is available in SmartScanner Professional

See Pricing