Description
serverlyr is a simple http server. serverlyr is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL.
Remediation
References
https://github.com/JacksonGL/NPM-Vuln-PoC/tree/master/directory-traversal/serverlyr
https://nodesecurity.io/advisories/365
Related Vulnerabilities
CVE-2022-25171 Vulnerability in npm package p4
CVE-2022-24431 Vulnerability in npm package abacus-ext-cmdline
CVE-2019-10789 Vulnerability in npm package curling
CVE-2022-25858 Vulnerability in maven package org.webjars.npm:terser
CVE-2022-41934 Vulnerability in maven package org.xwiki.platform:xwiki-platform-menu-ui