Description
Path traversal in buttle module versions <= 0.2.0 allows to read any file in the server.
Remediation
References
https://hackerone.com/reports/358112
Related Vulnerabilities
CVE-2023-38507 Vulnerability in npm package @strapi/admin
CVE-2021-34801 Vulnerability in npm package valine
CVE-2022-25758 Vulnerability in npm package scss-tokenizer
CVE-2022-41946 Vulnerability in maven package org.postgresql:postgresql
CVE-2023-29519 Vulnerability in maven package org.xwiki.platform:xwiki-platform-attachment-ui