Description
In blynk-server in Blynk before 0.39.7, Directory Traversal exists via a ../ in a URI that has /static or /static/js at the beginning, as demonstrated by reading the /etc/passwd file.
Remediation
References
https://github.com/blynkkk/blynk-server/issues/1256
https://github.com/blynkkk/blynk-server/releases/tag/v0.39.7
Related Vulnerabilities
CVE-2018-3787 Vulnerability in npm package simplehttpserver
CVE-2020-28442 Vulnerability in maven package org.webjars.bower:js-data
CVE-2021-39236 Vulnerability in maven package org.apache.ozone:ozone-main
CVE-2023-49375 Vulnerability in maven package com.jfinal:jfinal
CVE-2020-7686 Vulnerability in npm package rollup-plugin-dev-server