Lack of data validation - Path Traversal In swig
Description
Arbitrary local file read vulnerability during template rendering Directory traversal vulnerability in swig-templates thru 2.0.4 and swig thru 1.4.2, allows attackers to read arbitrary files via the include or extends tags.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version |
|---|---|---|
npm | ||
npm |
Aliases
1. 2. 3. 4.
References
1.