OSV 1.4.0 · github-reviewed · 修改于 2020-09-01 03:01
发布时间
2020-09-03 23:50
GitHub 审查时间
2020-09-01 03:01
NVD 发布时间
—
源文件
advisories/github-reviewed/2020/09/GHSA-f3vw-587g-r29g/GHSA-f3vw-587g-r29g.json
Versions of sapper prior to 0.27.11 are vulnerable to Path Traversal. It is possible to access sensitive files on the server through HTTP requests containing URL-encoded ../.
You may test a sapper application running in prod mode with curl -vvv http://localhost:3000/client/750af05c3a69ddc6073a/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/etc/passwd.
Upgrade to version 0.27.11 or later.