Description
A path traversal vulnerability in <= v0.2.6 of http-file-server npm module allows attackers to list files in arbitrary folders.
Remediation
References
https://hackerone.com/reports/570133
Related Vulnerabilities
CVE-2020-16041 Vulnerability in maven package org.webjars.npm:electron
CVE-2021-44878 Vulnerability in maven package org.pac4j:pac4j-core
CVE-2016-10735 Vulnerability in maven package org.jszip.redist:bootstrap
CVE-2021-43307 Vulnerability in maven package org.webjars.npm:semver-regex
CVE-2020-7679 Vulnerability in maven package org.webjars.bower:casperjs