Description
serve node module suffers from Improper Handling of URL Encoding by permitting access to ignored files if a filename is URL encoded.
Remediation
References
https://hackerone.com/reports/308721
Related Vulnerabilities
CVE-2020-7601 Vulnerability in npm package gulp-scss-lint
CVE-2019-17633 Vulnerability in maven package org.eclipse.che:assembly-wsmaster-war
CVE-2020-28477 Vulnerability in maven package org.webjars.npm:immer
CVE-2023-46998 Vulnerability in maven package org.webjars.bower:bootbox.js
CVE-2022-45690 Vulnerability in maven package cn.hutool:hutool-json