Description
A path traversal in statics-server exists in all version that allows an attacker to perform a path traversal when a symlink is used within the working directory.
Remediation
References
https://hackerone.com/reports/695416
Related Vulnerabilities
CVE-2023-28155 Vulnerability in maven package org.webjars:request
CVE-2023-32315 Vulnerability in maven package org.igniterealtime.openfire:xmppserver
CVE-2022-26336 Vulnerability in maven package org.apache.poi:poi-scratchpad
CVE-2018-1335 Vulnerability in maven package org.apache.tika:tika-server
CVE-2023-29526 Vulnerability in maven package org.xwiki.platform:xwiki-platform-rendering-async-api