Description
node-srv node module suffers from a Path Traversal vulnerability due to lack of validation of url, which allows a malicious user to read content of any file with known path.
Remediation
References
https://hackerone.com/reports/309124
Related Vulnerabilities
CVE-2022-36890 Vulnerability in maven package org.jenkins-ci.plugins:deployer-framework
CVE-2022-43401 Vulnerability in maven package org.jenkins-ci.plugins:script-security
CVE-2021-21331 Vulnerability in maven package com.datadoghq:datadog-api-client
CVE-2021-37137 Vulnerability in maven package io.netty:netty-codec