Path Traversal in restify-swagger-jsdoc
High severity
GitHub Reviewed
Published
Sep 3, 2020
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Description
Reviewed
Aug 31, 2020
Published to the GitHub Advisory Database
Sep 3, 2020
Last updated
Jan 9, 2023
Versions of
restify-swagger-jsdoc
prior to 3.2.1 are vulnerable to Path Traversal. The package fails to properly sanitize URLs, which may allow attackers to access server files outside theswagger-ui
folder by using relative paths.Recommendation
Upgrade to version 3.2.1 or later.
References