Description
index.js in Total.js Platform before 3.2.3 allows path traversal.
Remediation
References
https://blog.certimetergroup.com/it/articolo/security/total.js-directory-traversal-cve-2019-8903
https://github.com/totaljs/framework/commit/c37cafbf3e379a98db71c1125533d1e8d5b5aef7
https://github.com/totaljs/framework/commit/de16238d13848149f5d1dae51f54e397a525932b
Related Vulnerabilities
CVE-2020-35490 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2023-44487 Vulnerability in maven package org.eclipse.jetty.http2:http2-common
CVE-2023-26109 Vulnerability in npm package node-bluetooth-serial-port
CVE-2022-28156 Vulnerability in maven package com.surenpi.jenkins:phoenix-autotest