Description
serverlyr is a simple http server. serverlyr is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL.
Remediation
References
https://github.com/JacksonGL/NPM-Vuln-PoC/tree/master/directory-traversal/serverlyr
https://nodesecurity.io/advisories/365
Related Vulnerabilities
CVE-2022-21144 Vulnerability in npm package libxmljs
CVE-2011-3190 Vulnerability in maven package tomcat:tomcat-coyote
CVE-2021-21169 Vulnerability in npm package electron
CVE-2023-37961 Vulnerability in maven package org.jenkins-ci.plugins:assembla-auth
CVE-2022-35278 Vulnerability in maven package org.apache.activemq:artemis-web