Description
Bitty is a development web server tool that functions similar to `python -m SimpleHTTPServer`. Version 0.2.10 has a directory traversal vulnerability that is exploitable via the URL path in GET requests.
Remediation
References
https://nodesecurity.io/advisories/150
Related Vulnerabilities
CVE-2020-15095 Vulnerability in maven package org.webjars:npm
CVE-2018-14042 Vulnerability in maven package org.webjars:bootstrap-sass
CVE-2021-39152 Vulnerability in maven package com.thoughtworks.xstream:xstream
CVE-2022-24999 Vulnerability in maven package org.webjars.npm:qs
CVE-2020-6454 Vulnerability in maven package org.webjars.npm:electron