Description
serverlyr is a simple http server. serverlyr is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL.
Remediation
References
https://github.com/JacksonGL/NPM-Vuln-PoC/tree/master/directory-traversal/serverlyr
https://nodesecurity.io/advisories/365
Related Vulnerabilities
CVE-2021-32808 Vulnerability in maven package org.webjars.npm:ckeditor4
CVE-2021-23341 Vulnerability in maven package org.webjars.npm:prismjs
CVE-2021-41182 Vulnerability in maven package org.webjars:jquery-ui
CVE-2021-23380 Vulnerability in npm package roar-pidusage
CVE-2021-43797 Vulnerability in maven package io.netty:netty-codec-http