Description
The send package before 0.11.1 for Node.js allows attackers to obtain the root path via unspecified vectors.
Remediation
References
http://www.openwall.com/lists/oss-security/2016/04/20/11
http://www.securityfocus.com/bid/96435
https://nodesecurity.io/advisories/56
Related Vulnerabilities
CVE-2021-39154 Vulnerability in maven package com.thoughtworks.xstream:xstream
CVE-2020-2114 Vulnerability in maven package org.jenkins-ci.plugins:s3
CVE-2020-36049 Vulnerability in maven package org.webjars.npm:socket.io-parser
CVE-2021-4040 Vulnerability in maven package org.apache.activemq:artemis-core-client