Description
serve node module suffers from Improper Handling of URL Encoding by permitting access to ignored files if a filename is URL encoded.
Remediation
References
https://hackerone.com/reports/308721
Related Vulnerabilities
CVE-2021-21638 Vulnerability in maven package org.jenkins-ci.plugins:tfs
CVE-2020-28168 Vulnerability in maven package org.webjars.bower:axios
CVE-2015-6584 Vulnerability in npm package datatables
CVE-2022-23457 Vulnerability in maven package org.owasp.esapi:esapi
CVE-2023-34468 Vulnerability in maven package org.apache.nifi:nifi-dbcp-base