Root Path Disclosure

Affecting send package, versions <0.11.1

Report new vulnerabilities
Do your applications use this vulnerable package? Test your applications

Overview

Send is a library for streaming files from the file system as an http response. It supports partial responses (Ranges), conditional-GET negotiation, high test coverage, and granular events which may be leveraged to take appropriate actions in your application or framework.

Affected versions of this package are vulnerable to a Root Path Disclosure.

Remediation

Upgrade send to version 0.11.1 or higher. If a direct dependency update is not possible, use snyk wizard to patch this vulnerability.

References

Snyk patch available for versions:

CVSS Score

5.3
medium severity
  • Attack Vector
    Network
  • Attack Complexity
    Low
  • Privileges Required
    None
  • User Interaction
    None
  • Scope
    Unchanged
  • Confidentiality
    None
  • Integrity
    None
  • Availability
    Low
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Credit
Dinis Cruz
CVE
CVE-2015-8859
CWE
CWE-200
Snyk ID
npm:send:20151103
Disclosed
03 Nov, 2015
Published
06 Nov, 2015