Description
sspa is a server dedicated to single-page apps. sspa is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Remediation
References
https://github.com/JacksonGL/NPM-Vuln-PoC/blob/master/directory-traversal/sspa
https://nodesecurity.io/advisories/463
Related Vulnerabilities
CVE-2020-9498 Vulnerability in maven package org.apache.guacamole:guacamole
CVE-2018-15890 Vulnerability in maven package org.ethereum:ethereumj-core
CVE-2023-44487 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core
CVE-2020-28442 Vulnerability in maven package org.webjars.bower:js-data
CVE-2017-16881 Vulnerability in maven package org.b3log:symphony