Open redirect vulnerability in the serve-static plugin before 1.7.2 for Node.js, when mounted at the root, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a // (slash slash) followed by a domain in the PATH_INFO to the default URI.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Serve-static | Serve-static_project | * | 1.7.1 (including) |
Node-serve-static | Ubuntu | artful | * |
Node-serve-static | Ubuntu | upstream | * |
Node-serve-static | Ubuntu | utopic | * |
Node-serve-static | Ubuntu | vivid | * |
Node-serve-static | Ubuntu | wily | * |
Node-serve-static | Ubuntu | yakkety | * |
Node-serve-static | Ubuntu | zesty | * |