Description
`hftp` is a static http or ftp server `hftp` is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Remediation
References
https://github.com/JacksonGL/NPM-Vuln-PoC/tree/master/directory-traversal/hftp
https://nodesecurity.io/advisories/384
Related Vulnerabilities
CVE-2021-30246 Vulnerability in maven package org.webjars.bowergithub.kjur:jsrsasign
CVE-2023-42794 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core
CVE-2020-8132 Vulnerability in npm package pdf-image
CVE-2022-2216 Vulnerability in npm package parse-url
CVE-2021-22204 Vulnerability in npm package exiftool-vendored