Description
Node-RED-Dashboard before 2.26.2 allows ui_base/js/..%2f directory traversal to read files.
Remediation
References
https://github.com/node-red/node-red-dashboard/issues/669
https://github.com/node-red/node-red-dashboard/releases/tag/2.26.2
Related Vulnerabilities
CVE-2018-8026 Vulnerability in maven package org.apache.solr:solr-core
CVE-2021-21307 Vulnerability in maven package org.lucee:lucee
CVE-2022-39299 Vulnerability in npm package @node-saml/passport-saml
CVE-2017-16089 Vulnerability in npm package serverlyr
CVE-2022-24821 Vulnerability in maven package org.xwiki.platform:xwiki-platform-skin-skinx