CVE-2020-15779

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
15/07/2020
Last modified:
22/07/2020

Description

A Path Traversal issue was discovered in the socket.io-file package through 2.0.31 for Node.js. The socket.io-file::createFile message uses path.join with ../ in the name option, and the uploadDir and rename options determine the path.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:socket.io-file_project:socket.io-file:*:*:*:*:*:node.js:*:* 2.0.31 (including)