Description
desafio is a simple web server. desafio is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url, but is limited to accessing only .html files.
Remediation
References
https://github.com/JacksonGL/NPM-Vuln-PoC/blob/master/directory-traversal/desafio
https://nodesecurity.io/advisories/397
Related Vulnerabilities
CVE-2023-36478 Vulnerability in maven package org.eclipse.jetty.http3:http3-qpack
CVE-2019-16728 Vulnerability in maven package org.webjars.bower:dompurify
CVE-2020-5245 Vulnerability in maven package io.dropwizard:dropwizard-validation
CVE-2022-43403 Vulnerability in maven package org.jenkins-ci.plugins:script-security
CVE-2020-9480 Vulnerability in maven package org.apache.spark:spark-network-common_2.11