Description
`gomeplus-h5-proxy` is vulnerable to a directory traversal issue, allowing attackers to access any file in the system by placing '../' in the URL.
Remediation
References
https://github.com/JacksonGL/NPM-Vuln-PoC/tree/master/directory-traversal/gomeplus-h5-proxy
https://nodesecurity.io/advisories/350
Related Vulnerabilities
CVE-2021-27516 Vulnerability in maven package org.webjars.npm:urijs
CVE-2023-4853 Vulnerability in maven package io.quarkus:quarkus-keycloak-authorization
CVE-2012-0392 Vulnerability in maven package org.apache.struts.xwork:xwork-core
CVE-2019-19729 Vulnerability in npm package bson-objectid
CVE-2018-8811 Vulnerability in maven package org.opencms:opencms-core