Description
This affects all versions of package droppy. It is possible to traverse directories to fetch configuration files from a droopy server.
Remediation
References
https://github.com/silverwind/droppy/blob/master/server/server.js%23L845
https://snyk.io/vuln/SNYK-JS-DROPPY-1023656
Related Vulnerabilities
CVE-2018-1000548 Vulnerability in maven package com.umlet:umlet-swing
CVE-2020-7758 Vulnerability in npm package browserless-chrome
CVE-2017-3203 Vulnerability in maven package org.springframework.flex:spring-flex-core
CVE-2017-4952 Vulnerability in maven package com.vmware.xenon:xenon-common
CVE-2022-23496 Vulnerability in maven package nl.basjes.parse.useragent:yauaa-flink-table