Description
node-srv node module suffers from a Path Traversal vulnerability due to lack of validation of url, which allows a malicious user to read content of any file with known path.
Remediation
References
https://hackerone.com/reports/309124
Related Vulnerabilities
CVE-2021-3645 Vulnerability in npm package @viking04/merge
CVE-2021-27568 Vulnerability in maven package net.minidev:json-smart
CVE-2021-3690 Vulnerability in maven package io.undertow:undertow-core
CVE-2022-0350 Vulnerability in npm package vditor
CVE-2018-18854 Vulnerability in maven package io.spray:spray-json_2.10