Description
A path traversal in statics-server exists in all version that allows an attacker to perform a path traversal when a symlink is used within the working directory.
Remediation
References
https://hackerone.com/reports/695416
Related Vulnerabilities
CVE-2017-16116 Vulnerability in npm package string
CVE-2021-3859 Vulnerability in maven package io.undertow:undertow-core
CVE-2022-45398 Vulnerability in maven package org.zeroturnaround:cluster-stats
CVE-2018-1002204 Vulnerability in npm package adm-zip
CVE-2018-1000529 Vulnerability in maven package org.grails.plugins:fields