Description
curlrequest through 1.0.1 allows reading any file by populating the file parameter with user input.
Remediation
References
https://github.com/node-js-libs/curlrequest/blob/master/index.js#L239%2C
https://snyk.io/vuln/SNYK-JS-CURLREQUEST-568274
Related Vulnerabilities
CVE-2022-41404 Vulnerability in maven package org.ini4j:ini4j
CVE-2021-21293 Vulnerability in maven package org.http4s:blaze-core_2.13
CVE-2023-24057 Vulnerability in maven package ca.uhn.hapi.fhir:org.hl7.fhir.r4b
CVE-2021-23430 Vulnerability in npm package startserver
CVE-2022-28355 Vulnerability in maven package org.scala-js:scalajs-library_2.12