CVE-2018-3718: Medium severity zeit serve vulnerability
Published Jun 7, 2018
·Updated
serve node module suffers from Improper Handling of URL Encoding by permitting access to ignored files if a filename is URL encoded.
Affected Software
2 affected componentsFixes available
npm/serve<6.5.2
6.5.2
ZEIT Serve Node.js<6.5.2
Remediation
Patch Available
Event History
Jun 7, 2018
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
DescriptionWeakness
Aug 9, 2021
Advisory Published
10:24 PM
Frequently Asked Questions
1
What is the severity of CVE-2018-3718?
CVE-2018-3718 has a medium severity rating due to improper handling of URL encoding.
2
How do I fix CVE-2018-3718?
To fix CVE-2018-3718, upgrade the serve node module to version 6.5.2 or later.
3
What impact does CVE-2018-3718 have on my application?
CVE-2018-3718 may allow unauthorized access to ignored files through URL encoding.
4
Is CVE-2018-3718 a widely exploited vulnerability?
While there are no specific reports of widespread exploitation, it is important to address CVE-2018-3718 due to its potential risk.
5
What versions of the serve module are affected by CVE-2018-3718?
CVE-2018-3718 affects all versions of the serve module prior to 6.5.2.