Description
uv-tj-demo is a static file server. uv-tj-demo is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
Remediation
References
https://github.com/JacksonGL/NPM-Vuln-PoC/blob/master/directory-traversal/uv-tj-demo
https://nodesecurity.io/advisories/428
Related Vulnerabilities
CVE-2022-31129 Vulnerability in maven package org.webjars:momentjs
CVE-2023-30531 Vulnerability in maven package org.jenkins-ci.plugins:consul-kv-builder
CVE-2020-7021 Vulnerability in maven package org.elasticsearch:elasticsearch
CVE-2022-36094 Vulnerability in maven package org.xwiki.platform:xwiki-platform-web-templates