Fastify static是Fastify组织的一个威胁情报网络辅助工具。 Fastify static 10.1.0及之前版本存在路径遍历漏洞,该漏洞源于文件解析前未能拒绝请求路径名中的点-点路径段,导致未经身份验证的攻击者可以绕过基于路由路径限制的中间件,读取受保护URL前缀下的文件。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| @fastify/static | @fastify/static | < 10.1.1 |
affected |
10.1.1 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| @fastify/static | @fastify/static | 0 ~ 10.1.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet