Description
A path traversal vulnerability in <= v0.2.6 of http-file-server npm module allows attackers to list files in arbitrary folders.
Remediation
References
https://hackerone.com/reports/570133
Related Vulnerabilities
CVE-2022-25852 Vulnerability in npm package libpq
CVE-2023-33544 Vulnerability in maven package io.hawt:hawtio-system
CVE-2022-21213 Vulnerability in maven package org.webjars:mout
CVE-2022-25867 Vulnerability in maven package io.socket:socket.io-client
CVE-2021-39157 Vulnerability in npm package detect-character-encoding