CVE-2020-15779: Path Traversal
(updated )
A Path Traversal issue was discovered in the socket.io-file package for Node.js. The socket.io-file::createFile
message uses path.join with ../
in the name option, and the uploadDir
and rename options determine the path.
References
Detect and mitigate CVE-2020-15779 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →