Description
Bitpay/insight-api Insight-api version 5.0.0 and earlier contains a CWE-20: input validation vulnerability in transaction broadcast endpoint that can result in Full Path Disclosure. This attack appear to be exploitable via Web request.
Remediation
References
https://github.com/bitpay/insight-api/issues/542
Related Vulnerabilities
CVE-2019-6284 Vulnerability in maven package org.webjars.npm:node-sass
CVE-2020-9497 Vulnerability in maven package org.apache.guacamole:guacamole
CVE-2017-1000190 Vulnerability in maven package org.simpleframework:simple-xml
CVE-2019-10748 Vulnerability in npm package sequelize
CVE-2017-16152 Vulnerability in npm package static-html-server