Description
Bitpay/insight-api Insight-api version 5.0.0 and earlier contains a CWE-20: input validation vulnerability in transaction broadcast endpoint that can result in Full Path Disclosure. This attack appear to be exploitable via Web request.
Remediation
References
https://github.com/bitpay/insight-api/issues/542
Related Vulnerabilities
CVE-2023-22665 Vulnerability in maven package org.apache.jena:jena-arq
CVE-2022-25885 Vulnerability in npm package hummus
CVE-2022-34298 Vulnerability in maven package org.openidentityplatform.openam:openam-auth-nt
CVE-2022-21144 Vulnerability in npm package libxmljs
CVE-2021-23358 Vulnerability in maven package org.webjars.npm:underscore