Description
goserv is an http server. goserv is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Remediation
References
https://github.com/JacksonGL/NPM-Vuln-PoC/blob/master/directory-traversal/goserv
https://nodesecurity.io/advisories/473
Related Vulnerabilities
CVE-2022-40955 Vulnerability in maven package org.apache.inlong:sort-connector-base
CVE-2020-16040 Vulnerability in maven package org.webjars.npm:electron
CVE-2022-26850 Vulnerability in maven package org.apache.nifi:nifi-single-user-utils
CVE-2022-29237 Vulnerability in maven package org.opencastproject:opencast-ingest-service-impl
CVE-2023-1370 Vulnerability in maven package net.minidev:json-smart