Description
In blynk-server in Blynk before 0.39.7, Directory Traversal exists via a ../ in a URI that has /static or /static/js at the beginning, as demonstrated by reading the /etc/passwd file.
Remediation
References
https://github.com/blynkkk/blynk-server/issues/1256
https://github.com/blynkkk/blynk-server/releases/tag/v0.39.7
Related Vulnerabilities
CVE-2022-2932 Vulnerability in npm package mobiledoc-dom-renderer
CVE-2020-36649 Vulnerability in maven package org.webjars.bower:papaparse
CVE-2023-5572 Vulnerability in npm package @vrite/sdk
CVE-2023-47327 Vulnerability in maven package org.silverpeas.core:silverpeas-core-web
CVE-2020-7763 Vulnerability in npm package phantom-html-to-pdf