github.com/labstack/echo/v5 is vulnerable to Exposure of Information Through Directory Listing
81
High Risk
Affected versions of this package allow unintended directory disclosure when StaticWithConfig is used with Browse: true and no index file exists: directory listings are generated from the filesystem root instead of being constrained to StaticConfig.Root. An attacker can exploit this by requesting a browsable path (e.g., /) to enumerate files and directories outside the intended public directory, potentially discovering sensitive filenames, structure, and metadata such as sizes.
You are affected if you are using a version that falls within the vulnerable range and you set config.Browse=true.
github.com/labstack/echo/v5 is vulnerable to Exposure of Information Through Directory Listing in versions 5.0.0 - 5.0.1.
Upgrade the github.com/labstack/echo/v5 library to the patch version.
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant