CVE-2015-5688
Directory Traversal in geddy
EPSS 9.4%
Description
Versions 13.0.8 and earlier of geddy are vulnerable to a directory traversal attack via URI encoded attack vectors. ### Proof of Concept ``` http://localhost:4000/..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2fetc/passwd ``` ## Recommendation Update geddy to version >= 13.0.8
How to fix CVE-2015-5688
To remediate CVE-2015-5688, upgrade the affected package to a fixed version below.
- npm/geddy—upgrade to 13.0.8 or later
Is CVE-2015-5688 being exploited?
Moderate — EPSS is 9.4%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- from 0, < 13.0.8