{"id":"GHSA-rv49-54qp-fw42","aliases":[],"url":"https://o3.security/vulnerability/GHSA-rv49-54qp-fw42","summary":"Path Traversal in servey","details":"Versions of `servey` prior to 3.x are vulnerable to Path Traversal.  Due to insufficient input sanitization, attackers can access server files by using relative paths. \n\n\n## Recommendation\n\nUpgrade to the latest version","published":"2019-06-06T15:30:20Z","modified":"2020-08-31T18:36:18Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"servey","fixedVersion":"3.1.0"}],"fix":{"url":"https://github.com/typeorm/typeorm/commit/d46c8b0e6c0db56bb5976a4917e9f67a43715111","label":"typeorm/typeorm@d46c8b0"},"references":[{"type":"WEB","url":"https://github.com/typeorm/typeorm/commit/d46c8b0e6c0db56bb5976a4917e9f67a43715111"},{"type":"WEB","url":"https://hackerone.com/reports/355501"},{"type":"WEB","url":"https://www.npmjs.com/advisories/802"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2020-08-31T18:36:18Z"}}