Description
restafary is a REpresentful State Transfer API for Creating, Reading, Using, Deleting files on a server from the web. Restafary before 1.6.1 is able to set up a root path, which should only allow it to run inside of that root path it specified.
Remediation
References
https://nodesecurity.io/advisories/89
Related Vulnerabilities
CVE-2022-0341 Vulnerability in npm package vditor
CVE-2022-0868 Vulnerability in npm package urijs
CVE-2021-23363 Vulnerability in npm package kill-by-port
CVE-2018-1000136 Vulnerability in maven package org.webjars.npm:electron
CVE-2023-25766 Vulnerability in maven package org.jenkins-ci.plugins:azure-credentials