Description
serve node module before 6.4.9 suffers from a Path Traversal vulnerability due to not handling %2e (.) and %2f (/) and allowing them in paths, which allows a malicious user to view the contents of any directory with known path.
Remediation
References
https://github.com/zeit/serve/pull/316
https://hackerone.com/reports/307666
Related Vulnerabilities
CVE-2013-2133 Vulnerability in maven package org.wildfly:wildfly-ejb3
CVE-2022-31175 Vulnerability in npm package @ckeditor/ckeditor5-html-support
CVE-2017-4973 Vulnerability in maven package org.cloudfoundry.identity:cloudfoundry-identity-server
CVE-2023-37277 Vulnerability in maven package org.xwiki.platform:xwiki-platform-rest-server
CVE-2023-24449 Vulnerability in maven package org.jvnet.hudson.plugins:pwauth