Directory Traversal vulnerability in Foddy node-red-contrib-huemagic version 3.0.0, allows remote attackers to gain sensitive information via crafted request in res.sendFile API in hue-magic.js.
References
Link | Resource |
---|---|
https://github.com/Foddy/node-red-contrib-huemagic/issues/217 | Exploit Issue Tracking Patch |
Configurations
History
16 Aug 2023, 20:22
Type | Values Removed | Values Added |
---|---|---|
First Time |
Dgtl
Dgtl huemagic |
|
CWE | CWE-22 | |
CPE | cpe:2.3:a:dgtl:huemagic:3.0.0:*:*:*:*:node.js:*:* | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
References | (MISC) https://github.com/Foddy/node-red-contrib-huemagic/issues/217 - Exploit, Issue Tracking, Patch |
11 Aug 2023, 15:18
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-08-11 14:15
Updated : 2024-02-28 20:33
NVD link : CVE-2021-26504
Mitre link : CVE-2021-26504
CVE.ORG link : CVE-2021-26504
JSON object : View
Products Affected
dgtl
- huemagic
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')