Description
In blynk-server in Blynk before 0.39.7, Directory Traversal exists via a ../ in a URI that has /static or /static/js at the beginning, as demonstrated by reading the /etc/passwd file.
Remediation
References
https://github.com/blynkkk/blynk-server/releases/tag/v0.39.7
https://github.com/blynkkk/blynk-server/issues/1256
Related Vulnerabilities
CVE-2014-3488 Vulnerability in maven package io.netty:netty
CVE-2022-38180 Vulnerability in maven package io.ktor:ktor-client-core
CVE-2022-23540 Vulnerability in maven package org.webjars.npm:jsonwebtoken
CVE-2023-48241 Vulnerability in maven package org.xwiki.platform:xwiki-platform-search-solr-query
CVE-2022-38179 Vulnerability in maven package io.ktor:ktor-utils