Description
The html-pages node module contains a path traversal vulnerabilities that allows an attacker to read any file from the server with cURL.
Remediation
References
https://github.com/danielcardoso/html-pages/issues/2
https://hackerone.com/reports/306607
Related Vulnerabilities
CVE-2020-28448 Vulnerability in npm package multi-ini
CVE-2016-4433 Vulnerability in maven package org.apache.struts:struts2-core
CVE-2022-48285 Vulnerability in maven package org.webjars:jszip
CVE-2015-5258 Vulnerability in maven package org.springframework.social:spring-social-core
CVE-2022-1278 Vulnerability in maven package org.wildfly:wildfly-microprofile