Description
tinyserver2 is a webserver for static files. tinyserver2 is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL.
Remediation
References
https://github.com/JacksonGL/NPM-Vuln-PoC/tree/master/directory-traversal/tinyserver2
https://nodesecurity.io/advisories/371
Related Vulnerabilities
CVE-2023-24057 Vulnerability in maven package ca.uhn.hapi.fhir:org.hl7.fhir.validation
CVE-2022-0219 Vulnerability in maven package io.github.skylot:jadx-core
CVE-2023-22893 Vulnerability in npm package @strapi/plugin-users-permissions
CVE-2023-25572 Vulnerability in npm package ra-ui-materialui
CVE-2021-35515 Vulnerability in maven package org.apache.commons:commons-compress