Description
Bitty is a development web server tool that functions similar to `python -m SimpleHTTPServer`. Version 0.2.10 has a directory traversal vulnerability that is exploitable via the URL path in GET requests.
Remediation
References
https://nodesecurity.io/advisories/150
Related Vulnerabilities
CVE-2019-13173 Vulnerability in maven package org.webjars.npm:fstream
CVE-2022-43432 Vulnerability in maven package org.jenkins-ci.plugins:xframium
CVE-2018-3721 Vulnerability in npm package lodash.mergewith
CVE-2020-2140 Vulnerability in maven package org.jenkins-ci.plugins:audit-trail
CVE-2019-1010266 Vulnerability in maven package org.fujion.webjars:lodash