Description
gaoxuyan is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Remediation
References
https://github.com/JacksonGL/NPM-Vuln-PoC/tree/master/directory-traversal/gaoxuyan
https://nodesecurity.io/advisories/378
Related Vulnerabilities
CVE-2020-2221 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2018-1000644 Vulnerability in maven package org.eclipse.rdf4j:rdf4j-rio-trix
CVE-2017-5664 Vulnerability in maven package org.apache.tomcat:tomcat-catalina
CVE-2020-21122 Vulnerability in maven package com.bstek.ureport:ureport2-console
CVE-2018-1199 Vulnerability in maven package org.springframework.security:spring-security-config