Description
A path traversal vulnerability in <= v0.2.6 of http-file-server npm module allows attackers to list files in arbitrary folders.
Remediation
References
https://hackerone.com/reports/570133
Related Vulnerabilities
CVE-2016-10735 Vulnerability in maven package ua.mobius.media:bootstrap
CVE-2021-3807 Vulnerability in npm package ansi-regex
CVE-2020-36049 Vulnerability in maven package org.webjars.npm:socket.io-parser
CVE-2022-0155 Vulnerability in npm package follow-redirects
CVE-2022-28220 Vulnerability in maven package org.apache.james:james-server-protocols-imap4