Description
Bitty is a development web server tool that functions similar to `python -m SimpleHTTPServer`. Version 0.2.10 has a directory traversal vulnerability that is exploitable via the URL path in GET requests.
Remediation
References
https://nodesecurity.io/advisories/150
Related Vulnerabilities
CVE-2022-43411 Vulnerability in maven package org.jenkins-ci.plugins:gitlab-plugin
CVE-2021-26118 Vulnerability in maven package org.apache.activemq:artemis-openwire-protocol
CVE-2020-7780 Vulnerability in maven package com.softwaremill.akka-http-session:core_2.13
CVE-2023-22579 Vulnerability in npm package sequelize
CVE-2017-12628 Vulnerability in maven package org.apache.james:james-server