Versions 13.0.8 and earlier of geddy are vulnerable to a directory traversal attack via URI encoded attack vectors.
http://localhost:4000/..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2fetc/passwd
Update geddy to version >= 13.0.8
| Score | Percentile |
|---|---|
| 81.09% | 99.13% |
No CVSS scores in this advisory.
| Type | Value |
|---|---|
| GHSA | GHSA-333x-9vgq-v2j4 ↗ |
| CVE | CVE-2015-5688 ↗ |
| CWE id | Name |
|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
Vulnerable version ranges and first patched releases as published by GitHub.
| Ecosystem | Package | Vulnerable range | First patched | Vulnerable functions |
|---|---|---|---|---|
| npm | geddy | < 13.0.8 | 13.0.8 | — |