Description
zwserver is a weather web server. zwserver is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Remediation
References
https://github.com/JacksonGL/NPM-Vuln-PoC/tree/master/directory-traversal/zwserver
https://nodesecurity.io/advisories/372
Related Vulnerabilities
CVE-2022-0686 Vulnerability in npm package url-parse
CVE-2021-29485 Vulnerability in maven package io.ratpack:ratpack-session
CVE-2023-22580 Vulnerability in npm package sequelize
CVE-2019-5475 Vulnerability in maven package org.sonatype.nexus.plugins:nexus-yum-repository-plugin
CVE-2023-29215 Vulnerability in maven package org.apache.linkis:linkis-metadata-query-service-jdbc