CVE Vulnerabilities

CVE-2015-8859

Published: Jan 23, 2017 | Modified: Apr 20, 2025
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

The send package before 0.11.1 for Node.js allows attackers to obtain the root path via unspecified vectors.

Affected Software

NameVendorStart VersionEnd Version
SendSend_project*0.11.1 (excluding)
Node-sendUbuntuartful*
Node-sendUbuntubionic*
Node-sendUbuntucosmic*
Node-sendUbuntuesm-apps/bionic*
Node-sendUbuntuesm-apps/xenial*
Node-sendUbuntutrusty*
Node-sendUbuntuupstream*
Node-sendUbuntuwily*
Node-sendUbuntuxenial*
Node-sendUbuntuyakkety*
Node-sendUbuntuzesty*

References