Description
serverlyr is a simple http server. serverlyr is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL.
Remediation
References
https://github.com/JacksonGL/NPM-Vuln-PoC/tree/master/directory-traversal/serverlyr
https://nodesecurity.io/advisories/365
Related Vulnerabilities
CVE-2019-5475 Vulnerability in maven package org.sonatype.nexus.plugins:nexus-yum-repository-plugin
CVE-2021-41184 Vulnerability in maven package org.webjars.npm:jquery-ui
CVE-2023-33831 Vulnerability in npm package @frangoteam/fuxa
CVE-2021-21290 Vulnerability in maven package io.netty:netty-handler
CVE-2020-10992 Vulnerability in maven package com.linkedin.azkaban:azkaban-common