VDB
CVE-2018-3713
CVE-2018-3713
PUBLISHED
CVSS 6.5 MEDIUM
Path Traversal in angular-http-server
EPSS 1.47% · 72.6th percentile
Risk Scores
CVSS 3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS Score
1.47%
72.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| angular-http-server_project | angular-http-server | |
| npm | angular-http-server | 0 |
| HackerOne | angular-http-server node module | All versions |
Timeline
- CVE Published
- Mar 1, 2018 PoC Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 25, 2021 EPSS Score
- Oct 27, 2021 EPSS Score
- Dec 29, 2021 EPSS Score
- May 4, 2022 EPSS Score
- Jul 6, 2022 EPSS Score
- Sep 8, 2022 EPSS Score
- Nov 10, 2022 EPSS Score
- Jan 12, 2023 EPSS Score
References
- https://www.npmjs.com/advisories/589 url
- https://hackerone.com/reports/309120 url
- https://nvd.nist.gov/vuln/detail/CVE-2018-3713 advisory
- https://github.com/simonh1000/angular-http-server/pull/21 url
- https://github.com/simonh1000/angular-http-server/commit/34d4bd0cd0f00c46db30855a8c4aabae27eb0ac8 url
- https://github.com/advisories/GHSA-4rvg-955w-h68q advisory