Description
crud-file-server node module before 0.9.0 suffers from a Path Traversal vulnerability due to incorrect validation of url, which allows a malicious user to read content of any file with known path.
Remediation
References
https://github.com/omphalos/crud-file-server/commit/4fc3b404f718abb789f4ce4272c39c7a138c7a82
https://hackerone.com/reports/310690
Related Vulnerabilities
CVE-2021-29369 Vulnerability in npm package gnuplot
CVE-2017-14063 Vulnerability in maven package org.asynchttpclient:async-http-client
CVE-2020-12827 Vulnerability in npm package mjml
CVE-2022-43423 Vulnerability in maven package com.compuware.jenkins:compuware-scm-downloader
CVE-2020-14060 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind