Description
serverlyr is a simple http server. serverlyr is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL.
Remediation
References
https://github.com/JacksonGL/NPM-Vuln-PoC/tree/master/directory-traversal/serverlyr
https://nodesecurity.io/advisories/365
Related Vulnerabilities
CVE-2021-41269 Vulnerability in maven package com.cronutils:cron-utils
CVE-2017-3199 Vulnerability in maven package org.graniteds:granite-generator
CVE-2022-31053 Vulnerability in maven package com.clever-cloud:biscuit-java
CVE-2020-7706 Vulnerability in npm package connie-lang
CVE-2020-7633 Vulnerability in npm package apiconnect-cli-plugins