Description
The html-pages node module contains a path traversal vulnerabilities that allows an attacker to read any file from the server with cURL.
Remediation
References
https://github.com/danielcardoso/html-pages/issues/2
https://hackerone.com/reports/306607
Related Vulnerabilities
CVE-2023-3691 Vulnerability in maven package org.webjars.bowergithub.layui:layui
CVE-2023-29521 Vulnerability in maven package org.xwiki.platform:xwiki-platform-vfs-ui
CVE-2021-46089 Vulnerability in maven package org.jeecgframework.boot:jeecg-boot-base-core
CVE-2020-26259 Vulnerability in maven package com.thoughtworks.xstream:xstream
CVE-2019-9515 Vulnerability in maven package io.netty:netty-codec-http2