highcharts-export-server@1.0.21 vulnerabilities

Convert Highcharts.JS charts to static image files.

Direct Vulnerabilities

Known vulnerabilities in the highcharts-export-server package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • L
Information Exposure

highcharts-export-server is a Convert Highcharts.JS charts to static image files.

Affected versions of this package are vulnerable to Information Exposure. It allows for reading and outputting files served by other services on the internal network in which the export server is hosted. If the export server is exposed to the internet, this potentially allows a malicious user to gain read access to internal web-resources.The impact is limited to internal services that serve content via. HTTP(S), and requires the attacker to know internal hostnames/IP addresses.

How to fix Information Exposure?

Upgrade highcharts-export-server to version 2.1.0 or higher.

<2.1.0