{"id":"GHSA-7x92-2j68-h32c","aliases":[],"url":"https://o3.security/vulnerability/GHSA-7x92-2j68-h32c","summary":"Directory Traversal in featurebook","details":"Affected versions of `featurebook` resolve relative file paths, resulting in a directory traversal vulnerability. A malicious actor can use this vulnerability to access files outside of the intended directory root, which may result in the disclosure of private files on the vulnerable system.\n\nThe `featurebook` package is not intended to be run in production code nor to be exposed to an untrusted network.\n\n\n## Proof of Concept\n```\nGET /../../../../../../../../../../etc/passwd HTTP/1.1\nhost:foo\n```\n\n\n## Recommendation\n\nNo direct patch is currently available.\n\nAt this time, the best mitigation is to ensure that `featurebook` is not running in production or exposed to an untrusted network.","published":"2020-09-01T19:03:02Z","modified":"2020-08-31T18:27:38Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"featurebook","fixedVersion":null}],"fix":null,"references":[{"type":"WEB","url":"https://hackerone.com/reports/296305"},{"type":"WEB","url":"https://www.npmjs.com/advisories/556"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2020-08-31T18:27:38Z"}}