Description
sspa is a server dedicated to single-page apps. sspa is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Remediation
References
https://github.com/JacksonGL/NPM-Vuln-PoC/blob/master/directory-traversal/sspa
https://nodesecurity.io/advisories/463
Related Vulnerabilities
CVE-2021-43116 Vulnerability in maven package com.alibaba.nacos:nacos-client
CVE-2021-42697 Vulnerability in maven package com.typesafe.akka:akka-http_2.13
CVE-2021-23337 Vulnerability in maven package org.fujion.webjars:lodash
CVE-2020-28500 Vulnerability in maven package org.webjars.bower:lodash
CVE-2022-41714 Vulnerability in npm package fastest-json-copy