Path Traversal in simplehttpserver
Moderate severity
GitHub Reviewed
Published
Dec 6, 2018
to the GitHub Advisory Database
•
Updated Sep 12, 2023
Description
Published to the GitHub Advisory Database
Dec 6, 2018
Reviewed
Jun 16, 2020
Last updated
Sep 12, 2023
All versions of
simplehttpserver
are vulnerable to Path Traversal.This vulnerability allows an attacker to access files outside the webroot since it allows symlink navigation in the URL.
Recommendation
No fix is currently available. Do not use
simplehttpserver
in production or consider using an alternative module until a fix is made available.References