Directory Traversal Affecting larvitbase-api package, versions <0.5.5
Threat Intelligence
EPSS
0.1% (43rd
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-JS-LARVITBASEAPI-459899
- published 20 Aug 2019
- disclosed 20 Aug 2019
- credit Vasiliy Ermilov
Introduced: 20 Aug 2019
CVE-2019-5479 Open this link in a new tabHow to fix?
Upgrade larvitbase-api
to version 0.5.5 or higher.
Overview
larvitbase-api is a part of larbitbase - a scaled down version of Express.
Affected versions of this package are vulnerable to Directory Traversal. The server dynamically loads some parts of the code. As long as the path to required module is partially depend on the URL, an attacker can cause code to load that was not intended to run on the server.
References
CVSS Scores
version 3.1