Description
serve46 is a static file server. serve46 is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Remediation
References
https://github.com/JacksonGL/NPM-Vuln-PoC/blob/master/directory-traversal/serve46
https://nodesecurity.io/advisories/456
Related Vulnerabilities
CVE-2021-3807 Vulnerability in npm package ansi-regex
CVE-2021-3690 Vulnerability in maven package io.undertow:undertow-core
CVE-2020-9480 Vulnerability in maven package org.apache.spark:spark-network-common_2.11
CVE-2021-32723 Vulnerability in npm package prismjs
CVE-2022-41965 Vulnerability in maven package org.opencastproject:opencast-engage-paella-player