public@0.1.2 vulnerabilities
Run http server hosting static files with specified public dir & port
-
latest version
0.1.5
-
latest non vulnerable version
-
first published
13 years ago
-
latest version published
5 years ago
-
licenses detected
- >=0
Direct Vulnerabilities
Known vulnerabilities in the public package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.Vulnerability | Vulnerable Version |
---|---|
public is a package used for running static file hosting server with specified public dir & port. Also it supports a "direcotry index" like Apache httpd. Affected versions of this package are vulnerable to Directory Traversal via Symlink. How to fix Directory Traversal? Upgrade |
<0.1.3
|
public is a package used for running static file hosting server with specified public dir & port. Also it supports a "direcotry index" like Apache httpd. Affected versions of this package are vulnerable to Cross-site Scripting (XSS) attacks. It allows to embed HTML in file names, which (in certain conditions) might lead to execute malicious JavaScript. Vulnerable Code:
How to fix Cross-site Scripting (XSS)? Upgrade |
<0.1.4
|
public is a package used for running static file hosting server with specified public dir & port. Also it supports a "direcotry index" like Apache httpd. Affected versions of this package are vulnerable to Cross-site Scripting (XSS) attacks. It allows to embed HTML in file names, which (in certain conditions) might lead to execute malicious JavaScript. Vulnerable Code:
How to fix Cross-site Scripting (XSS)? Upgrade |
<0.1.4
|
public is a static file hosting server with specified public dir & port. Affected versions of this package are vulnerable to Directory Traversal via lack of file path sanitization which causes that any file on the server might be read by malicious user. How to fix Directory Traversal? Upgrade |
<0.1.3
|
public is a static file hosting server with specified public dir & port. Affected versions of this package are vulnerable to Directory Traversal via lack of file path sanitization which causes that any file on the server might be read by malicious user. How to fix Directory Traversal? Upgrade |
<0.1.3
|