Description
A path traversal in statics-server exists in all version that allows an attacker to perform a path traversal when a symlink is used within the working directory.
Remediation
References
https://hackerone.com/reports/695416
Related Vulnerabilities
CVE-2021-21616 Vulnerability in maven package org.biouno:uno-choice
CVE-2018-1000632 Vulnerability in maven package org.jenkins-ci.dom4j:dom4j
CVE-2021-27515 Vulnerability in maven package org.webjars.npm:url-parse
CVE-2022-29770 Vulnerability in maven package com.xuxueli:xxl-job
CVE-2023-34602 Vulnerability in maven package org.jeecgframework.boot:jeecg-boot-base-core