MEDIUM
The send package before 0.11.1 for Node.js allows attackers to obtain the root path via unspecified vectors
Published Jan 23, 2017
5.3
MEDIUMCVSS 3.1
EPSS 4.70%
Description
The send package before 0.11.1 for Node.js allows attackers to obtain the root path via unspecified vectors.
Affected products
No data.
- < 0.11.1
No data.
No Red Hat product state for this CVE.
send
npm
Introduced 0 Fixed 0.11.1
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | send | 0 | 0.11.1 |
Remediation
No remediation recorded yet.
Weaknesses (1)
References (9)
- http://www.openwall.com/lists/oss-security/2016/04/20/11 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- http://www.securityfocus.com/bid/96435 vdb-entryx_refsource_BIDBroken LinkThird Party AdvisoryVDB Entry
- https://github.com/advisories/GHSA-jgqf-hwc5-hh37 Advisory
- https://github.com/expressjs/serve-static/blob/master/HISTORY.md#181--2015-01-20
- https://github.com/pillarjs/send/commit/98a5b89982b38e79db684177cf94730ce7fc7aed
- https://github.com/pillarjs/send/pull/70
- https://nodesecurity.io/advisories/56 x_refsource_CONFIRMBroken LinkPatchVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2015-8859
- https://web.archive.org/web/20200227192016/https://www.securityfocus.com/bid/96435/
| Link | Providers | Tags |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2016/04/20/11 | mailing-listx_refsource_MLISTMailing ListThird Party Advisory | |
| http://www.securityfocus.com/bid/96435 | vdb-entryx_refsource_BIDBroken LinkThird Party AdvisoryVDB Entry | |
| https://github.com/advisories/GHSA-jgqf-hwc5-hh37 | Advisory | |
| https://github.com/expressjs/serve-static/blob/master/HISTORY.md#181--2015-01-20 | ||
| https://github.com/pillarjs/send/commit/98a5b89982b38e79db684177cf94730ce7fc7aed | ||
| https://github.com/pillarjs/send/pull/70 | ||
| https://nodesecurity.io/advisories/56 | x_refsource_CONFIRMBroken LinkPatchVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2015-8859 | ||
| https://web.archive.org/web/20200227192016/https://www.securityfocus.com/bid/96435/ |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jan 23, 2017
Updated Aug 6, 2024
Reserved Apr 20, 2016
Link CVE-2015-8859
CISA Vulnrichment
GHSA-JGQF-HWC5-HH37 Updated n/a