Description
node-srv node module suffers from a Path Traversal vulnerability due to lack of validation of url, which allows a malicious user to read content of any file with known path.
Remediation
References
https://hackerone.com/reports/309124
Related Vulnerabilities
CVE-2019-11002 Vulnerability in npm package materialize-css
CVE-2015-1370 Vulnerability in maven package org.webjars.npm:marked
CVE-2021-21347 Vulnerability in maven package com.thoughtworks.xstream:xstream
CVE-2014-7205 Vulnerability in npm package bassmaster
CVE-2023-34478 Vulnerability in maven package org.apache.shiro:shiro-web