Description
yttivy is a static file server. yttivy is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Remediation
References
https://github.com/JacksonGL/NPM-Vuln-PoC/blob/master/directory-traversal/yttivy
https://nodesecurity.io/advisories/441
Related Vulnerabilities
CVE-2023-29517 Vulnerability in maven package org.xwiki.platform:xwiki-platform-office-viewer
CVE-2022-31183 Vulnerability in maven package co.fs2:fs2-io_sjs1_3
CVE-2022-25927 Vulnerability in maven package org.webjars.npm:github-com-faisalman-ua-parser-js
CVE-2020-19697 Vulnerability in maven package org.webjars.bowergithub.pandao:editor.md
CVE-2017-1000228 Vulnerability in maven package org.webjars.npm:ejs