Description
restafary is a REpresentful State Transfer API for Creating, Reading, Using, Deleting files on a server from the web. Restafary before 1.6.1 is able to set up a root path, which should only allow it to run inside of that root path it specified.
Remediation
References
https://nodesecurity.io/advisories/89
Related Vulnerabilities
CVE-2021-41117 Vulnerability in npm package keypair
CVE-2020-7693 Vulnerability in maven package org.webjars.npm:sockjs
CVE-2020-21125 Vulnerability in maven package com.bstek.ureport:ureport2-console
CVE-2022-1295 Vulnerability in maven package org.webjars.bowergithub.alvarotrigo:fullpage.js
CVE-2022-21126 Vulnerability in maven package com.github.samtools:htsjdk