Description
`gomeplus-h5-proxy` is vulnerable to a directory traversal issue, allowing attackers to access any file in the system by placing '../' in the URL.
Remediation
References
https://github.com/JacksonGL/NPM-Vuln-PoC/tree/master/directory-traversal/gomeplus-h5-proxy
https://nodesecurity.io/advisories/350
Related Vulnerabilities
CVE-2022-25898 Vulnerability in npm package jsrsasign
CVE-2020-10199 Vulnerability in maven package org.sonatype.nexus:nexus-extdirect
CVE-2022-39353 Vulnerability in maven package org.webjars.npm:xmldom__xmldom
CVE-2023-40815 Vulnerability in maven package org.opencrx:opencrx-core-models
CVE-2020-28268 Vulnerability in npm package controlled-merge