Description
Node-RED-Dashboard before 2.26.2 allows ui_base/js/..%2f directory traversal to read files.
Remediation
References
https://github.com/node-red/node-red-dashboard/issues/669
https://github.com/node-red/node-red-dashboard/releases/tag/2.26.2
Related Vulnerabilities
CVE-2020-5280 Vulnerability in maven package org.http4s:http4s-server
CVE-2023-2507 Vulnerability in npm package clevertap-cordova
CVE-2021-41086 Vulnerability in npm package jsuites
CVE-2020-6836 Vulnerability in maven package org.webjars.npm:hot-formula-parser
CVE-2017-7674 Vulnerability in maven package org.apache.tomcat:tomcat-catalina