CVE-2019-15596

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
18/12/2019
Last modified:
27/12/2019

Description

A path traversal in statics-server exists in all version that allows an attacker to perform a path traversal when a symlink is used within the working directory.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:statics-server_project:statics-server:*:*:*:*:*:node.js:*:* 0.0.9 (including)


References to Advisories, Solutions, and Tools