Description
picard is a micro framework. picard is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Remediation
References
https://github.com/JacksonGL/NPM-Vuln-PoC/blob/master/directory-traversal/picard
https://nodesecurity.io/advisories/436
Related Vulnerabilities
CVE-2020-14966 Vulnerability in maven package org.webjars.bowergithub.kjur:jsrsasign
CVE-2021-32770 Vulnerability in npm package gatsby-source-wordpress
CVE-2021-37304 Vulnerability in maven package org.jeecgframework.boot:jeecg-boot-base
CVE-2022-46166 Vulnerability in maven package de.codecentric:spring-boot-admin-server
CVE-2020-9498 Vulnerability in maven package org.apache.guacamole:guacamole