Description
When users add resources to the resource center with a relation path will cause path traversal issues and only for logged-in users. You could upgrade to version 3.0.0 or higher
Remediation
References
http://www.openwall.com/lists/oss-security/2022/11/01/13
https://lists.apache.org/thread/pbdzqf9ntxyvs4cr0x2dgk9zlf43btz8
Related Vulnerabilities
CVE-2020-28500 Vulnerability in npm package lodash
CVE-2021-45456 Vulnerability in maven package org.apache.kylin:kylin-server-base
CVE-2021-41580 Vulnerability in npm package passport-oauth2
CVE-2020-7770 Vulnerability in npm package json8
CVE-2022-43431 Vulnerability in maven package com.compuware.jenkins:compuware-strobe-measurement