OSV 1.4.0 · github-reviewed · 修改于 2023-09-12 07:14
发布时间
2020-09-02 00:44
GitHub 审查时间
2020-09-01 02:19
NVD 发布时间
—
源文件
advisories/github-reviewed/2020/09/GHSA-cqv6-7fwc-8m3c/GHSA-cqv6-7fwc-8m3c.json
Affected versions of xtalk are vulnerable to directory traversal, allowing access to the filesystem by placing "../" in the URL.
Example request:
GET /../../../../../../../../../../etc/passwd HTTP/1.1
host:localhost
No patch is currently available for this vulnerability, and the package has not been updated since 2014.
The best mitigation is currently to avoid using this package, and using a different, functionally equivalent package.