GMS-2017-316: Directory Traversal
elding
is vulnerable to a directory traversal issue, allowing an attacker to access the filesystem by placing “../” in the url. /nThe files accessible, however, are limited to files with a file extension. Sending a GET
request to /../../../etc/passwd
, for example, will return a on etc/passwd/index.js.
References
Detect and mitigate GMS-2017-316 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →