CVE-2017-16130: Path Traversal
(updated )
exxxxxxxxxxx is an HTTP eX Frame Google Style JavaScript Guide. exxxxxxxxxxx is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing ../
in the url. Accessible files are restricted to those with a file extension. Files with no extension such as /etc/passwd
throw an error.
References
Detect and mitigate CVE-2017-16130 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →