{"id":"CVE-2019-5415","details":"A bug in handling the ignore files and directories feature in serve 6.5.3 allows an attacker to read a file or list the directory that the victim has not allowed access to.","aliases":["GHSA-v588-qcp3-jv46"],"modified":"2026-04-10T04:19:27.958965Z","published":"2019-03-21T16:01:05.483Z","references":[{"type":"EVIDENCE","url":"https://hackerone.com/reports/330724"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/zeit/serve","events":[{"introduced":"0"},{"last_affected":"33602e01255b9c6f8ff6f010dc8f860ba3ef6a22"}],"database_specific":{"versions":[{"introduced":"0"},{"last_affected":"6.5.3"}]}}],"versions":["0.1.0","0.1.1","0.2.1","0.3.0","0.4.0","0.5.0","0.6.0","0.6.1","0.8.0","0.8.1","0.8.2","0.9.0","0.9.1","2.0.0","2.1.0","2.1.1","2.1.2","2.2.0","2.3.0","2.4.0","2.4.1","2.4.2","2.4.3","2.4.4","3.0.0","3.0.1","3.0.2","3.1.0","3.2.0","3.2.1","3.2.10","3.2.2","3.2.3","3.2.4","3.2.5","3.2.6","3.2.7","3.2.8","3.2.9","3.3.0","3.3.1","3.4.0","3.4.1","4.0.0","4.0.1","4.0.2","5.0.0","5.0.1","5.0.2","5.0.3","5.0.4","5.1.0","5.1.1","5.1.2","5.1.3","5.1.4","5.1.5","5.2.0","5.2.1","5.2.2","5.2.3","5.2.4","6.0.0","6.0.1","6.0.2","6.0.3","6.0.4","6.0.5","6.0.6","6.1.0","6.2.0","6.3.0","6.3.1","6.4.0","6.4.1","6.4.10","6.4.11","6.4.2","6.4.3","6.4.4","6.4.5","6.4.6","6.4.7","6.4.8","6.4.9","6.5.0","6.5.1","6.5.2","6.5.3","v2.1.1","v2.1.2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-5415.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}