Description
A Path traversal exists in http_server which allows an attacker to read arbitrary system files.
Remediation
References
https://hackerone.com/reports/692262
Related Vulnerabilities
CVE-2020-28496 Vulnerability in npm package three
CVE-2019-14653 Vulnerability in maven package org.webjars.npm:editor.md
CVE-2020-1951 Vulnerability in maven package org.apache.tika:tika-parsers
CVE-2019-1003041 Vulnerability in maven package org.jenkins-ci.plugins:script-security
CVE-2021-41038 Vulnerability in npm package @theia/plugin-ext