Description
Bitpay/insight-api Insight-api version 5.0.0 and earlier contains a CWE-20: input validation vulnerability in transaction broadcast endpoint that can result in Full Path Disclosure. This attack appear to be exploitable via Web request.
Remediation
References
https://github.com/bitpay/insight-api/issues/542
Related Vulnerabilities
CVE-2020-5230 Vulnerability in maven package org.opencastproject:base
CVE-2020-8237 Vulnerability in maven package org.webjars.bower:json-bigint
CVE-2022-30973 Vulnerability in maven package org.apache.tika:tika
CVE-2021-23337 Vulnerability in maven package org.fujion.webjars:lodash
CVE-2020-5259 Vulnerability in maven package org.webjars.bower:dojox