Information Exposure Affecting rendertron-middleware package, versions <0.1.3
Threat Intelligence
EPSS
0.39% (74th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-JS-RENDERTRONMIDDLEWARE-72700
- published 18 Dec 2018
- disclosed 17 Dec 2018
- credit Unknown
Introduced: 17 Dec 2018
CVE-2017-18355 Open this link in a new tabHow to fix?
Upgrade rendertron-middleware
to version 0.1.3 or higher.
Overview
rendertron-middleware is an Express middleware for Rendertron
Affected versions of this package are vulnerable to Information Exposure. Installed packages are exposed by node_modules in Rendertron, allowed remote attackers to read absolute paths on the server by examining the _where
attribute of package.json files.
References
CVSS Scores
version 3.1