CVE Vulnerabilities

CVE-2015-1164

Published: Jan 21, 2015 | Modified: Sep 08, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

Open redirect vulnerability in the serve-static plugin before 1.7.2 for Node.js, when mounted at the root, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a // (slash slash) followed by a domain in the PATH_INFO to the default URI.

Affected Software

Name Vendor Start Version End Version
Serve-static Serve-static_project * 1.7.1 (including)
Node-serve-static Ubuntu artful *
Node-serve-static Ubuntu upstream *
Node-serve-static Ubuntu utopic *
Node-serve-static Ubuntu vivid *
Node-serve-static Ubuntu wily *
Node-serve-static Ubuntu yakkety *
Node-serve-static Ubuntu zesty *

References