Description
A path traversal in statics-server exists in all version that allows an attacker to perform a path traversal when a symlink is used within the working directory.
Remediation
References
https://hackerone.com/reports/695416
Related Vulnerabilities
CVE-2023-40816 Vulnerability in maven package org.opencrx:opencrx-core-models
CVE-2020-11022 Vulnerability in maven package org.fujion.webjars:jquery
CVE-2021-43821 Vulnerability in maven package org.opencastproject:opencast-ingest-service-impl
CVE-2015-9239 Vulnerability in npm package ansi2html
CVE-2023-29922 Vulnerability in maven package tech.powerjob:powerjob