Description
Versions less than 0.1.4 of the static file server module fancy-server are vulnerable to directory traversal. An attacker can provide input such as `../` to read files outside of the served directory.
Remediation
References
https://nodesecurity.io/advisories/9
Related Vulnerabilities
CVE-2023-2479 Vulnerability in npm package appium-desktop
CVE-2021-3137 Vulnerability in maven package org.xwiki.commons:xwiki-commons
CVE-2022-47551 Vulnerability in maven package io.apiman:apiman-manager-api-rest-impl
CVE-2019-16550 Vulnerability in maven package org.jenkins-ci.plugins.m2release:m2release
CVE-2021-25122 Vulnerability in maven package org.apache.tomcat:tomcat-catalina