漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)
Vulnerability Description
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, on Windows hosts, an encoded backslash (%5C) in the request path decodes to \, which the Windows path resolver treats as a separator. serve-static then resolves a single URL segment such as admin\secret.txt into a nested file under the root and serves it, letting an attacker read static files meant to be protected behind prefix-mounted middleware. This vulnerability is fixed in 4.12.25.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
honojs hono 路径遍历漏洞
Vulnerability Description
honojs hono是honojs的Web服务器。 honojs hono 4.12.25之前版本存在路径遍历漏洞,该漏洞源于Windows主机上请求路径中的编码反斜杠(%5C)被解码为\\,导致路径解析器将其视为分隔符,从而使攻击者能够读取本应受前缀挂载中间件保护的静态文件。
CVSS Information
N/A
Vulnerability Type
N/A