Description
node-simple-router is a minimalistic router for Node. node-simple-router is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL.
Remediation
References
https://github.com/JacksonGL/NPM-Vuln-PoC/tree/master/directory-traversal/node-simple-router
https://nodesecurity.io/advisories/352
Related Vulnerabilities
CVE-2021-41079 Vulnerability in maven package org.apache.tomcat:tomcat
CVE-2021-21353 Vulnerability in npm package pug-code-gen
CVE-2019-10352 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2020-7701 Vulnerability in npm package madlib-object-utils
CVE-2021-28657 Vulnerability in maven package org.apache.tika:tika-parsers