Description
The html-pages node module contains a path traversal vulnerabilities that allows an attacker to read any file from the server with cURL.
Remediation
References
https://github.com/danielcardoso/html-pages/issues/2
https://hackerone.com/reports/306607
Related Vulnerabilities
CVE-2022-25851 Vulnerability in maven package org.webjars.npm:jpeg-js
CVE-2020-8840 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2022-28150 Vulnerability in maven package com.synopsys.jenkinsci:ownership
CVE-2022-31777 Vulnerability in maven package org.apache.spark:spark-core_2.13