Path traversal in pillarjs send - CVE-2014-6394
Published: October 14, 2019
Vulnerability details
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to the affected software uses a partial comparison for verifying whether a directory is within the document root. A remote attacker can send a specially crafted HTTP request and access restricted directories on the system, as demonstrated using "public-restricted" under a "public" directory.
Affected software
Fedora
nodejs-send
How to mitigate CVE-2014-6394
nodejs-send - addressed in versions 0.3.0-4.el6, 0.3.0-4.el7, 0.3.0-4.fc21