Description
angular-http-server node module suffers from a Path Traversal vulnerability due to lack of validation of possibleFilename, which allows a malicious user to read content of any file with known path.
Remediation
References
https://hackerone.com/reports/309120
Related Vulnerabilities
CVE-2016-3081 Vulnerability in maven package org.apache.struts:struts2-core
CVE-2021-43862 Vulnerability in npm package jquery.terminal
CVE-2020-28847 Vulnerability in npm package valine
CVE-2022-42003 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2022-25863 Vulnerability in npm package gatsby-plugin-mdx