Path Traversal Vulnerability in Node Module Affecting File Access
CVE-2018-3731

7.5HIGH

Key Information:

Vendor

Hackerone

Vendor
CVE Published:
7 June 2018

What is CVE-2018-3731?

This vulnerability involves a lack of validation in the public node module, which allows an attacker to exploit file paths to gain unauthorized access. By manipulating filePath inputs, a malicious user can read sensitive content from any file with a known path. This can lead to significant confidentiality breaches, making it crucial for developers to implement proper input validation and access controls to mitigate such risks.

Affected Version(s)

public node module All versions

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.