Description
curlrequest through 1.0.1 allows reading any file by populating the file parameter with user input.
Remediation
References
https://github.com/node-js-libs/curlrequest/blob/master/index.js#L239%2C
https://snyk.io/vuln/SNYK-JS-CURLREQUEST-568274
Related Vulnerabilities
CVE-2022-42467 Vulnerability in maven package org.apache.isis.core:isis-core-config
CVE-2021-23337 Vulnerability in maven package org.fujion.webjars:lodash
CVE-2022-37262 Vulnerability in npm package steal
CVE-2021-3815 Vulnerability in npm package @fabiocaccamo/utils.js
CVE-2019-11003 Vulnerability in maven package org.webjars.npm:materialize-css