Description
The html-pages node module contains a path traversal vulnerabilities that allows an attacker to read any file from the server with cURL.
Remediation
References
https://github.com/danielcardoso/html-pages/issues/2
https://hackerone.com/reports/306607
Related Vulnerabilities
CVE-2022-23080 Vulnerability in npm package directus
CVE-2018-1000820 Vulnerability in maven package org.neo4j.procedure:apoc
CVE-2019-1003041 Vulnerability in maven package org.jenkins-ci.plugins:script-security
CVE-2014-3600 Vulnerability in maven package org.apache.activemq:activemq-core
CVE-2020-16022 Vulnerability in maven package org.webjars.npm:electron