Description
pooledwebsocket is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Remediation
References
https://github.com/JacksonGL/NPM-Vuln-PoC/blob/master/directory-traversal/pooledwebsocket
https://nodesecurity.io/advisories/341
Related Vulnerabilities
CVE-2022-22984 Vulnerability in npm package snyk-mvn-plugin
CVE-2016-10735 Vulnerability in maven package com.loopeer.android:bootstrap
CVE-2020-29455 Vulnerability in npm package liveaddress
CVE-2023-24620 Vulnerability in maven package com.esotericsoftware.yamlbeans:yamlbeans
CVE-2021-21429 Vulnerability in maven package org.openapitools:openapi-generator-maven-plugin