Description
Node-RED-Dashboard before 2.26.2 allows ui_base/js/..%2f directory traversal to read files.
Remediation
References
https://github.com/node-red/node-red-dashboard/issues/669
https://github.com/node-red/node-red-dashboard/releases/tag/2.26.2
Related Vulnerabilities
CVE-2018-5673 Vulnerability in maven package org.webjars.npm:dojo
CVE-2016-10693 Vulnerability in npm package pm2-kafka
CVE-2019-1010266 Vulnerability in maven package org.webjars.npm:lodash
CVE-2019-5448 Vulnerability in npm package yarn
CVE-2019-16550 Vulnerability in maven package org.jenkins-ci.plugins.m2release:m2release