Description
curlrequest through 1.0.1 allows reading any file by populating the file parameter with user input.
Remediation
References
https://github.com/node-js-libs/curlrequest/blob/master/index.js#L239%2C
https://snyk.io/vuln/SNYK-JS-CURLREQUEST-568274
Related Vulnerabilities
CVE-2016-10735 Vulnerability in maven package org.webjars.bowergithub.twbs:bootstrap
CVE-2022-41250 Vulnerability in maven package com.meowlomo.jenkins:scm-httpclient
CVE-2021-32828 Vulnerability in maven package org.nuxeo.ecm.platform:nuxeo-platform-oauth
CVE-2021-31811 Vulnerability in maven package org.apache.pdfbox:pdfbox
CVE-2020-6428 Vulnerability in maven package org.webjars.npm:electron