Description
node-srv node module suffers from a Path Traversal vulnerability due to lack of validation of url, which allows a malicious user to read content of any file with known path.
Remediation
References
https://hackerone.com/reports/309124
Related Vulnerabilities
CVE-2015-2080 Vulnerability in maven package org.eclipse.jetty:jetty-http
CVE-2021-46708 Vulnerability in maven package org.webjars:swagger-ui
CVE-2023-26108 Vulnerability in npm package @nestjs/core
CVE-2023-41037 Vulnerability in maven package org.webjars.npm:github-com-openpgpjs-openpgpjs
CVE-2020-14195 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind