Description
A Path traversal exists in http_server which allows an attacker to read arbitrary system files.
Remediation
References
https://hackerone.com/reports/692262
Related Vulnerabilities
CVE-2022-45135 Vulnerability in maven package org.apache.cocoon:cocoon-databases-impl
CVE-2020-15095 Vulnerability in maven package org.webjars.bower:npm
CVE-2023-26135 Vulnerability in npm package flatnest
CVE-2023-50578 Vulnerability in maven package net.mingsoft:ms-mcms
CVE-2022-1330 Vulnerability in maven package org.webjars.bower:fullpage