Description
Bitpay/insight-api Insight-api version 5.0.0 and earlier contains a CWE-20: input validation vulnerability in transaction broadcast endpoint that can result in Full Path Disclosure. This attack appear to be exploitable via Web request.
Remediation
References
https://github.com/bitpay/insight-api/issues/542
Related Vulnerabilities
CVE-2021-3795 Vulnerability in npm package semver-regex
CVE-2015-1840 Vulnerability in npm package jquery-ujs
CVE-2022-44729 Vulnerability in maven package org.apache.xmlgraphics:batik-transcoder
CVE-2021-39194 Vulnerability in maven package com.charleskorn.kaml:kaml
CVE-2022-41255 Vulnerability in maven package org.jenkins-ci.plugins:cons3rt