Description
A path traversal vulnerability was found in module static-resource-server 1.7.2 that allows unauthorized read access to any file on the server by appending slashes in the URL.
Remediation
References
https://hackerone.com/reports/432600
Related Vulnerabilities
CVE-2020-7760 Vulnerability in maven package org.webjars.bower:codemirror
CVE-2018-9206 Vulnerability in maven package org.webjars.bower:blueimp-file-upload
CVE-2022-31069 Vulnerability in npm package @finastra/nestjs-proxy
CVE-2019-18797 Vulnerability in npm package node-sass
CVE-2023-44487 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core