Description
A path traversal vulnerability in <= v0.2.6 of http-file-server npm module allows attackers to list files in arbitrary folders.
Remediation
References
https://hackerone.com/reports/570133
Related Vulnerabilities
CVE-2023-27095 Vulnerability in maven package cn.hippo4j:hippo4j-core
CVE-2018-16485 Vulnerability in npm package m-server
CVE-2023-40826 Vulnerability in maven package org.pf4j:pf4j
CVE-2021-23434 Vulnerability in npm package object-path
CVE-2022-45210 Vulnerability in maven package org.jeecgframework.boot:jeecg-module-system