Description
picard is a micro framework. picard is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Remediation
References
https://github.com/JacksonGL/NPM-Vuln-PoC/blob/master/directory-traversal/picard
https://nodesecurity.io/advisories/436
Related Vulnerabilities
CVE-2021-25946 Vulnerability in npm package nconf-toml
CVE-2020-9483 Vulnerability in maven package org.apache.skywalking:oap-server
CVE-2022-30500 Vulnerability in maven package com.jflyfox:jflyfox_jfinal
CVE-2021-23425 Vulnerability in npm package trim-off-newlines
CVE-2021-34371 Vulnerability in maven package org.neo4j:neo4j