Description
Bitpay/insight-api Insight-api version 5.0.0 and earlier contains a CWE-20: input validation vulnerability in transaction broadcast endpoint that can result in Full Path Disclosure. This attack appear to be exploitable via Web request.
Remediation
References
https://github.com/bitpay/insight-api/issues/542
Related Vulnerabilities
CVE-2020-9298 Vulnerability in maven package com.netflix.spinnaker.orca:orca-core
CVE-2021-23820 Vulnerability in npm package json-pointer
CVE-2014-0050 Vulnerability in maven package commons-fileupload:commons-fileupload
CVE-2020-36378 Vulnerability in npm package aaptjs
CVE-2017-16138 Vulnerability in maven package org.webjars:mime