Description
Path traversal vulnerability in version up to v1.1.3 in serve-here.js npm module allows attackers to list any file in arbitrary folder.
Remediation
References
https://hackerone.com/reports/569966
Related Vulnerabilities
CVE-2022-2900 Vulnerability in maven package org.webjars.npm:parse-url
CVE-2022-41935 Vulnerability in maven package org.xwiki.platform:xwiki-platform-livetable-ui
CVE-2010-2076 Vulnerability in maven package org.apache.axis2:axis2-kernel
CVE-2022-37423 Vulnerability in maven package org.neo4j.procedure:apoc