Description
whispercast is a file server. whispercast is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Remediation
References
https://github.com/JacksonGL/NPM-Vuln-PoC/blob/master/directory-traversal/whispercast
https://nodesecurity.io/advisories/466
Related Vulnerabilities
CVE-2021-23376 Vulnerability in npm package ffmpegdotjs
CVE-2019-15477 Vulnerability in maven package org.jooby:jooby
CVE-2022-43426 Vulnerability in maven package io.jenkins.plugins:s3explorer
CVE-2022-36904 Vulnerability in maven package org.jenkins-ci.plugins:repository-connector
CVE-2022-29172 Vulnerability in maven package org.webjars.bower:auth0-lock