Description
node-srv node module suffers from a Path Traversal vulnerability due to lack of validation of url, which allows a malicious user to read content of any file with known path.
Remediation
References
https://hackerone.com/reports/309124
Related Vulnerabilities
CVE-2023-46998 Vulnerability in maven package org.webjars.bowergithub.makeusabrew:bootbox
CVE-2020-28496 Vulnerability in npm package three
CVE-2023-40809 Vulnerability in maven package org.opencrx:opencrx-core-models
CVE-2019-10768 Vulnerability in maven package org.webjars.bowergithub.angular:angular
CVE-2011-2481 Vulnerability in maven package org.apache.tomcat:tomcat-catalina