Description
`gomeplus-h5-proxy` is vulnerable to a directory traversal issue, allowing attackers to access any file in the system by placing '../' in the URL.
Remediation
References
https://nodesecurity.io/advisories/350
https://github.com/JacksonGL/NPM-Vuln-PoC/tree/master/directory-traversal/gomeplus-h5-proxy
Related Vulnerabilities
CVE-2023-27562 Vulnerability in npm package n8n
CVE-2022-28220 Vulnerability in maven package org.apache.james.protocols:protocols-netty
CVE-2022-25858 Vulnerability in maven package org.webjars.npm:terser
CVE-2024-36401 Vulnerability in maven package org.geoserver:gs-wms
CVE-2023-30522 Vulnerability in maven package org.jenkins-ci.plugins:fogbugz