CVE-2015-1164 – serve-static
Package
Manager: npm
Name: serve-static
Vulnerable Version: >=0 <1.7.2 || >=1.7.0 <1.7.2
Severity
Level: Low
CVSS v3.1: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N
CVSS v4.0: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
EPSS: 0.003 pctl0.52844
Details
Open Redirect in serve-static Versions of `serve-static` prior to 1.6.5 ( or 1.7.x prior to 1.7.2 ) are affected by an open redirect vulnerability on some browsers when configured to mount at the root directory. ## Proof of Concept A link to `http://example.com//www.google.com/%2e%2e` will redirect to `//www.google.com/%2e%2e` Some browsers will interpret this as `http://www.google.com/%2e%2e`, resulting in an external redirect. ## Recommendation Version 1.7.x: Update to version 1.7.2 or later. Version 1.6.x: Update to version 1.6.5 or later.
Metadata
Created: 2020-08-31T22:57:02Z
Modified: 2021-09-23T20:59:30Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/08/GHSA-c3x7-gjmx-r2ff/GHSA-c3x7-gjmx-r2ff.json
CWE IDs: ["CWE-601"]
Alternative ID: GHSA-c3x7-gjmx-r2ff
Finding: F156
Auto approve: 1