Description
Node-RED-Dashboard before 2.26.2 allows ui_base/js/..%2f directory traversal to read files.
Remediation
References
https://github.com/node-red/node-red-dashboard/issues/669
https://github.com/node-red/node-red-dashboard/releases/tag/2.26.2
Related Vulnerabilities
CVE-2020-6459 Vulnerability in npm package electron
CVE-2016-3506 Vulnerability in maven package com.oracle:ojdbc8
CVE-2018-11697 Vulnerability in maven package org.webjars.npm:node-sass
CVE-2021-37695 Vulnerability in npm package ckeditor4
CVE-2020-6463 Vulnerability in maven package org.webjars.npm:electron