CVE-2018-3712
Directory Traversal in serve
6.5
MEDIUM
CVSS 3.1
EPSS 0.68%
Description
Affected versions of `serve` do not properly handle `%2e` (.) and `%2f` (/) characters, and allow the, characters to be used in paths. This can be used to traverse the directory tree and list content of any directory the user running the process has access to. Mitigating factors: This vulnerability only allows listing of directory contents and does not allow reading of arbitrary files. ## Recommendation Update to version 6.4.9 later.
How to fix CVE-2018-3712
To remediate CVE-2018-3712, upgrade the affected package to a fixed version below.
- —upgrade to 6.4.9 or later
Is CVE-2018-3712 being exploited?
Low — EPSS is 0.7%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 6.4.9
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.5 | CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |