Description
A path traversal vulnerability was found in module static-resource-server 1.7.2 that allows unauthorized read access to any file on the server by appending slashes in the URL.
Remediation
References
https://hackerone.com/reports/432600
Related Vulnerabilities
CVE-2022-36094 Vulnerability in maven package org.xwiki.platform:xwiki-platform-web-templates
CVE-2023-39022 Vulnerability in maven package opensymphony:oscore
CVE-2020-7725 Vulnerability in npm package worksmith
CVE-2022-23464 Vulnerability in maven package com.nepxion:discovery-plugin-admin-center
CVE-2021-37137 Vulnerability in maven package io.netty:netty-codec