Description
node-simple-router is a minimalistic router for Node. node-simple-router is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL.
Remediation
References
https://github.com/JacksonGL/NPM-Vuln-PoC/tree/master/directory-traversal/node-simple-router
https://nodesecurity.io/advisories/352
Related Vulnerabilities
CVE-2021-21267 Vulnerability in npm package schema-inspector
CVE-2019-14772 Vulnerability in maven package org.webjars.npm:verdaccio
CVE-2020-28500 Vulnerability in maven package org.webjars.npm:lodash
CVE-2022-23616 Vulnerability in maven package org.xwiki.platform:xwiki-platform-administration-ui
CVE-2022-25645 Vulnerability in maven package org.webjars.npm:dset