Intel

AIKIDO-2024-10042

hono is vulnerable to Path Traversal

Path TraversalCVE-2024-32869 Published Apr 23, 2024

75

High Risk

This Affects:

JShono
0.0.1 - 4.2.6
Fixed in 4.2.7
Are you affected? Scan for Free

TL;DR

Affected versions of the package are vulnerable to path traversal. When using serveStatic with Deno, an attacker can traverse directories and access files that should not be accessible.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

hono is vulnerable to Path Traversal in versions 0.0.1 - 4.2.6.

How to fix this

Upgrade the hono library to the patch version.