Package
kibana-9.2-iamguarded
Component
@hono/node-server
Latest update
Aliases
5.9
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Justification
Impact
GHSA-frvp-7c67-39w9 is exploitable only on Windows hosts: the middleware bypass depends on Windows resolving a decoded backslash (%5C) as a path separator when serving static files. On Linux a backslash is a literal filename character, so a request such as /admin%5Csecret.txt cannot resolve into the guarded directory. This package ships only in Linux container images, so an adversary cannot reach the vulnerable code path.
Status