Description
sspa is a server dedicated to single-page apps. sspa is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Remediation
References
https://nodesecurity.io/advisories/463
https://github.com/JacksonGL/NPM-Vuln-PoC/blob/master/directory-traversal/sspa
Related Vulnerabilities
CVE-2020-7726 Vulnerability in npm package safe-object2
CVE-2020-8131 Vulnerability in npm package yarn
CVE-2022-27340 Vulnerability in maven package net.mingsoft:ms-mcms
CVE-2019-17495 Vulnerability in maven package org.webjars.bower:swagger-ui
CVE-2021-22096 Vulnerability in maven package org.springframework:spring-core