Description
serve node module suffers from Improper Handling of URL Encoding by permitting access to ignored files if a filename is URL encoded.
Remediation
References
https://hackerone.com/reports/308721
Related Vulnerabilities
CVE-2018-16459 Vulnerability in npm package exceljs
CVE-2022-24819 Vulnerability in maven package org.xwiki.platform:xwiki-platform-web-templates
CVE-2023-27602 Vulnerability in maven package org.apache.linkis:linkis-dist
CVE-2023-32068 Vulnerability in maven package org.xwiki.platform:xwiki-platform-url-api
CVE-2022-0839 Vulnerability in maven package org.liquibase:liquibase-core