Description
A path traversal vulnerability was found in module static-resource-server 1.7.2 that allows unauthorized read access to any file on the server by appending slashes in the URL.
Remediation
References
https://hackerone.com/reports/432600
Related Vulnerabilities
CVE-2020-2207 Vulnerability in maven package org.jenkins-ci.plugins:vncviewer
CVE-2021-23382 Vulnerability in npm package postcss
CVE-2020-13933 Vulnerability in maven package org.apache.shiro:shiro-web
CVE-2023-26920 Vulnerability in maven package org.webjars.npm:fast-xml-parser
CVE-2020-7778 Vulnerability in npm package systeminformation