Hidden Directories Always Servedinert
Versions 1.1.1 and earlier of
inert are vulnerable to an information leakage vulnerability which causes files in hidden directories to be served, even when showHidden is false.
The inert directory handler always allows files in hidden directories to be served, even when
showHidden is false.
Update to version >= 1.1.1.
reportedInitial report by Gil PedersenOct 17th, 2015
publishedAdvisory publishedDec 16th, 2014