You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to LoopBackJS Announcements
Description
A security leak exposing loopback-component-storage to directory traversal attack. The component was exposed to a vulnerability where an attacker could use a command to retrieve the content of the server.js file of a LoopBack application and crash the server.
Versions affected
loopback-component-storage 3.0.0 and earlier. Since this affects a component, it applies to both LoopBack v2 and v3 apps.