Description ZEIT Next.js 4 before 4.2.3 has Directory Traversal under the /_next request namespace. Remediation References CVE-2018-6184 Related Vulnerabilities Moodle Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2019-3808) WordPress Plugin Product Filter for WooCommerce Security Bypass (8.1.1) Python Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-2183) Atlassian Confluence CVE-2020-29448 Vulnerability (CVE-2020-29448) Python CVE-2020-27619 Vulnerability (CVE-2020-27619) Severity High Classification CVE-2018-6184 CWE-22 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Tags Missing Update Known Vulnerabilities