Vulnerability Description
This affects all versions of package static-dev-server. This is because when paths from users to the root directory are joined, the assets for the path accessed are relative to that of the root directory.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Static-Dev-Server Project | Static-Dev-Server | 1.0.0 |
Related Weaknesses (CWE)
References
- https://gist.github.com/lirantal/5550bcd0bdf92c1b56fbb20e141fe5bdExploitThird Party Advisory
- https://security.snyk.io/vuln/SNYK-JS-STATICDEVSERVER-3149917ExploitThird Party Advisory
- https://gist.github.com/lirantal/5550bcd0bdf92c1b56fbb20e141fe5bdExploitThird Party Advisory
- https://security.snyk.io/vuln/SNYK-JS-STATICDEVSERVER-3149917ExploitThird Party Advisory
FAQ
What is CVE-2022-25848?
CVE-2022-25848 is a vulnerability with a CVSS score of 7.5 (HIGH). This affects all versions of package static-dev-server. This is because when paths from users to the root directory are joined, the assets for the path accessed are relative to that of the root direct...
How severe is CVE-2022-25848?
CVE-2022-25848 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-25848?
Check the references section above for vendor advisories and patch information. Affected products include: Static-Dev-Server Project Static-Dev-Server.