原始 OSV JSON{
"id": "GHSA-4rvg-955w-h68q",
"aliases": [
"CVE-2018-3713"
],
"details": "Affected versions of `angular-http-server` are vulnerable to path traversal allowing a remote attacker to read files from the server that uses `angular-http-server`.\n\n## Recommendation\n\nUpdate to version 1.6.0 or later.\n\n:exclamation: Note: This was originally thought to be fixed in version 1.4.3, though according to [this issue](https://github.com/ossf-cve-benchmark/ossf-cve-benchmark/issues/117#issuecomment-803872454) the vulnerability was not completely fixed until version 1.6.0.",
"summary": "Path Traversal in angular-http-server",
"affected": [
{
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"fixed": "1.6.0"
}
]
}
],
"package": {
"name": "angular-http-server",
"ecosystem": "npm"
}
}
],
"modified": "2023-03-01T01:19:07Z",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
}
],
"published": "2018-07-26T14:47:40Z",
"references": [
{
"url": "https://nvd.nist.gov/vuln/detail/CVE-2018-3713",
"type": "ADVISORY"
},
{
"url": "https://github.com/simonh1000/angular-http-server/pull/21",
"type": "WEB"
},
{
"url": "https://github.com/simonh1000/angular-http-server/commit/34d4bd0cd0f00c46db30855a8c4aabae27eb0ac8",
"type": "WEB"
},
{
"url": "https://hackerone.com/reports/309120",
"type": "WEB"
},
{
"url": "https://github.com/advisories/GHSA-4rvg-955w-h68q",
"type": "ADVISORY"
},
{
"url": "https://www.npmjs.com/advisories/589",
"type": "WEB"
}
],
"schema_version": "1.4.0",
"database_specific": {
"cwe_ids": [
"CWE-22"
],
"severity": "MODERATE",
"github_reviewed": true,
"nvd_published_at": "2018-06-07T02:29:00Z",
"github_reviewed_at": "2020-06-16T20:59:07Z"
}
}