koa-static-cache@3.2.1 vulnerabilities

Static cache for koa

Direct Vulnerabilities

Known vulnerabilities in the koa-static-cache package. This does not include vulnerabilities belonging to this package’s dependencies.

Vulnerability Vulnerable Version
Directory Traversal

koa-static-cache is Static cache for koa.

Affected versions of the package are vulnerable to Directory Traversal. When in dynamic mode, a malicious user can traverse through the servers files, by entering %2E%2E/ into the url, allowing the attacker to obtain the contents of any file on the server's filesystem.

How to fix Directory Traversal?

Upgrade koa-static-cache to versions 4.1.1, 5.1.1 or higher.

<4.1.1 >=5.0.0 <5.1.1