Description
The html-pages node module contains a path traversal vulnerabilities that allows an attacker to read any file from the server with cURL.
Remediation
References
https://github.com/danielcardoso/html-pages/issues/2
https://hackerone.com/reports/306607
Related Vulnerabilities
CVE-2023-36542 Vulnerability in maven package org.apache.nifi:nifi-record-serialization-services
CVE-2022-25853 Vulnerability in npm package semver-tags
CVE-2021-32809 Vulnerability in npm package ckeditor4
CVE-2020-36618 Vulnerability in npm package whois
CVE-2019-1010206 Vulnerability in maven package com.github.kevinsawicki:http-request