Bugzilla – Bug 899320
VUL-0: CVE-2014-6394: nodejs-send: directory traversal vulnerability
Last modified: 2014-10-02 12:05:26 UTC
When relying on the root option to restrict file access it may be possible for an application consumer to escape out of the restricted directory and access files in a similarly named directory. For example, static(_dirname + '/public') would allow access to _dirname + '/public-restricted'. Upstream commit: https://github.com/visionmedia/send/commit/9c6ca9b2c0b880afd3ff91ce0d211213c5fa5f9a Corresponding pull request: https://github.com/visionmedia/send/pull/59 CVE request: http://seclists.org/oss-sec/2014/q3/640
bugbot adjusting priority
Hi, openSUSE product series didn't have the package "nodejs-send".