Description
curlrequest through 1.0.1 allows reading any file by populating the file parameter with user input.
Remediation
References
https://github.com/node-js-libs/curlrequest/blob/master/index.js#L239%2C
https://snyk.io/vuln/SNYK-JS-CURLREQUEST-568274
Related Vulnerabilities
CVE-2022-28355 Vulnerability in maven package org.scala-js:scalajs-library_2.11
CVE-2022-29002 Vulnerability in maven package com.xuxueli:xxl-job
CVE-2020-6858 Vulnerability in maven package com.hotels.styx:styx-components
CVE-2020-8244 Vulnerability in maven package org.webjars.npm:bl
CVE-2023-25570 Vulnerability in maven package com.ctrip.framework.apollo:apollo