CVE-2018-3731
Path Traversal in public
7.5
HIGH
CVSS 3.1
EPSS 0.35%
Description
Versions of `public` before 0.1.3 are vulnerable to path traversal. This is due to lack of file path sanitization which could lead to any file the parent process has access to on the server to be read by malicious user. ## Recommendation Update to version 0.1.3 or later.
How to fix CVE-2018-3731
To remediate CVE-2018-3731, upgrade the affected package to a fixed version below.
- —upgrade to 0.1.3 or later
Is CVE-2018-3731 being exploited?
Low — EPSS is 0.3%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 0.1.3
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |