All versions of package easy-static-server are vulnerable to Directory Traversal due to missing input sanitization and sandboxes being employed to the req.url user input that is passed to the server code.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: snyk

Published: 2022-12-20T00:00:00

Updated: 2022-12-20T00:00:00

Reserved: 2022-02-24T00:00:00


Link: CVE-2022-25931

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-12-20T05:15:11.587

Modified: 2022-12-29T18:45:08.617


Link: CVE-2022-25931

JSON object: View

cve-icon Redhat Information

No data.

CWE