Description
A path traversal vulnerability in <= v0.2.6 of http-file-server npm module allows attackers to list files in arbitrary folders.
Remediation
References
https://hackerone.com/reports/570133
Related Vulnerabilities
CVE-2020-13619 Vulnerability in npm package locutus
CVE-2021-23438 Vulnerability in npm package mpath
CVE-2022-26585 Vulnerability in maven package net.mingsoft:ms-mcms
CVE-2016-10735 Vulnerability in maven package org.webjars.bowergithub.twbs:bootstrap
CVE-2021-27516 Vulnerability in maven package org.webjars.bower:urijs