CVE-2019-5417: Path Traversal
Published Mar 17, 2019
·Updated
A path traversal vulnerability in serve npm package version 7.0.1 allows the attackers to read content of arbitrary files on the remote server.
Affected Software
1 affected component
ZEIT Serve Node.js>=7.0.1<7.3.1
Event History
Mar 17, 2019
CVE Published
via MITRE·07:24 PM
Data Sourced
via MITRE·07:24 PM
DescriptionWeakness
Mar 21, 2019
Data Sourced
via NVD·04:01 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2019-5417?
CVE-2019-5417 is classified as a high severity vulnerability due to its potential for remote file access.
2
How do I fix CVE-2019-5417?
To fix CVE-2019-5417, upgrade the serve npm package to version 7.3.1 or later.
3
What impact does CVE-2019-5417 have on affected systems?
CVE-2019-5417 allows attackers to exploit path traversal to gain access to sensitive files on the server.
4
Which versions of the serve package are affected by CVE-2019-5417?
CVE-2019-5417 affects serve npm package versions between 7.0.1 and 7.3.1.
5
Who is responsible for the serve package affected by CVE-2019-5417?
The serve package affected by CVE-2019-5417 is maintained by Zeit.