Description
The html-pages node module contains a path traversal vulnerabilities that allows an attacker to read any file from the server with cURL.
Remediation
References
https://hackerone.com/reports/306607
https://github.com/danielcardoso/html-pages/issues/2
Related Vulnerabilities
CVE-2020-26256 Vulnerability in npm package @fast-csv/parse
CVE-2021-3822 Vulnerability in npm package jsoneditor
CVE-2021-4264 Vulnerability in maven package org.webjars.npm:dustjs-linkedin
CVE-2016-10735 Vulnerability in maven package org.webjars.bower:bootstrap
CVE-2021-43980 Vulnerability in maven package org.apache.tomcat:tomcat