Description
Bitty is a development web server tool that functions similar to `python -m SimpleHTTPServer`. Version 0.2.10 has a directory traversal vulnerability that is exploitable via the URL path in GET requests.
Remediation
References
https://nodesecurity.io/advisories/150
Related Vulnerabilities
CVE-2021-35516 Vulnerability in maven package org.apache.commons:commons-compress
CVE-2017-1000404 Vulnerability in maven package se.diabol.jenkins.pipeline:delivery-pipeline-plugin
CVE-2018-21268 Vulnerability in npm package traceroute
CVE-2022-22984 Vulnerability in npm package snyk-docker-plugin
CVE-2016-6797 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core