Description
serveryaozeyan is a simple HTTP server. serveryaozeyan is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL.
Remediation
References
https://github.com/JacksonGL/NPM-Vuln-PoC/tree/master/directory-traversal/serveryaozeyan
https://nodesecurity.io/advisories/355
Related Vulnerabilities
CVE-2021-3810 Vulnerability in npm package code-server
CVE-2020-8123 Vulnerability in npm package strapi
CVE-2020-16022 Vulnerability in maven package org.webjars.npm:electron
CVE-2020-8136 Vulnerability in npm package fastify-multipart
CVE-2022-43429 Vulnerability in maven package com.compuware.jenkins:compuware-topaz-for-total-test