Information Exposure Affecting serve package, versions <7.0.0


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
0.22% (45th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Information Exposure vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDnpm:serve:20180531
  • published3 Jun 2018
  • disclosed31 May 2018
  • credittungpun

Introduced: 31 May 2018

CVE-2018-3809  (opens in a new tab)
CWE-200  (opens in a new tab)

How to fix?

Upgrade serve to version 7.0.0 or higher.

Overview

serve is a static file serving and directory listing.

Affected versions of this package are vulnerable to Information Exposure. An attacker could bypasses the ignore files/directories feature and read a file or list the directory that the victim has not allowed access to.

NOTE: This vulnerability has also been identified as: CVE-2019-5415

CVSS Base Scores

version 3.1