CVE-2016-10528

CVE-2016-10528

Vendor Hackerone
Product restafary node module
Weakness CWE-22 · Path traversal
Published May 31, 2018
Last update September 17, 2024

CVSS base score

What the vulnerability does

01Description

restafary is a REpresentful State Transfer API for Creating, Reading, Using, Deleting files on a server from the web. Restafary before 1.6.1 is able to set up a root path, which should only allow it to run inside of that root path it specified.

Key dates

02Disclosure timeline

May 31, 2018 CVE published
September 17, 2024 Record updated