Description
In blynk-server in Blynk before 0.39.7, Directory Traversal exists via a ../ in a URI that has /static or /static/js at the beginning, as demonstrated by reading the /etc/passwd file.
Remediation
References
https://github.com/blynkkk/blynk-server/issues/1256
https://github.com/blynkkk/blynk-server/releases/tag/v0.39.7
Related Vulnerabilities
CVE-2023-24187 Vulnerability in maven package com.bstek.ureport:ureport2-core
CVE-2022-31170 Vulnerability in maven package org.webjars.npm:openzeppelin__contracts-upgradeable
CVE-2018-1002202 Vulnerability in maven package net.lingala.zip4j:zip4j
CVE-2023-3308 Vulnerability in maven package com.whaleal.icefrog:icefrog-all
CVE-2023-50102 Vulnerability in maven package com.jfinal:jfinal