Description
restafary is a REpresentful State Transfer API for Creating, Reading, Using, Deleting files on a server from the web. Restafary before 1.6.1 is able to set up a root path, which should only allow it to run inside of that root path it specified.
Remediation
References
https://nodesecurity.io/advisories/89
Related Vulnerabilities
CVE-2020-7680 Vulnerability in maven package org.webjars.npm:docsify
CVE-2020-7961 Vulnerability in maven package com.liferay.portal:portal-impl
CVE-2020-7708 Vulnerability in npm package @irrelon/path
CVE-2020-28435 Vulnerability in npm package ffmpeg-sdk
CVE-2020-12642 Vulnerability in maven package com.epam.reportportal:service-api