Description
A path traversal vulnerability was found in module static-resource-server 1.7.2 that allows unauthorized read access to any file on the server by appending slashes in the URL.
Remediation
References
https://hackerone.com/reports/432600
Related Vulnerabilities
CVE-2020-35490 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2019-10352 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2020-28283 Vulnerability in npm package libnested
CVE-2018-17420 Vulnerability in maven package com.zrlog:zrlog
CVE-2010-1622 Vulnerability in maven package org.springframework:spring-beans