Description
`gomeplus-h5-proxy` is vulnerable to a directory traversal issue, allowing attackers to access any file in the system by placing '../' in the URL.
Remediation
References
https://github.com/JacksonGL/NPM-Vuln-PoC/tree/master/directory-traversal/gomeplus-h5-proxy
https://nodesecurity.io/advisories/350
Related Vulnerabilities
CVE-2021-23358 Vulnerability in npm package underscore
CVE-2021-41183 Vulnerability in maven package org.webjars.npm:jquery-ui
CVE-2020-7681 Vulnerability in npm package marscode
CVE-2022-23620 Vulnerability in maven package org.xwiki.platform:xwiki-platform-skin-skinx
CVE-2021-23439 Vulnerability in npm package file-upload-with-preview