CVE-2015-8859
בינונית 5.3
תיאור (מקור, אנגלית)
The send package before 0.11.1 for Node.js allows attackers to obtain the root path via unspecified vectors.
מדדים
- CVSS 3.1
-
5.3 (MEDIUM)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
מוצרים מושפעים
send_project: send
קישורים
- https://nodesecurity.io/advisories/56 Broken LinkPatchVendor Advisory
- https://nodesecurity.io/advisories/56 Broken LinkPatchVendor Advisory
- http://www.openwall.com/lists/oss-security/2016/04/20/11 Mailing ListThird Party Advisory
- http://www.securityfocus.com/bid/96435 Broken LinkThird Party AdvisoryVDB Entry
- http://www.openwall.com/lists/oss-security/2016/04/20/11 Mailing ListThird Party Advisory
- http://www.securityfocus.com/bid/96435 Broken LinkThird Party AdvisoryVDB Entry