Description
curlrequest through 1.0.1 allows reading any file by populating the file parameter with user input.
Remediation
References
https://github.com/node-js-libs/curlrequest/blob/master/index.js#L239%2C
https://snyk.io/vuln/SNYK-JS-CURLREQUEST-568274
Related Vulnerabilities
CVE-2023-29215 Vulnerability in maven package org.apache.linkis:linkis-metadata-query-service-jdbc
CVE-2021-21160 Vulnerability in maven package org.webjars.npm:electron
CVE-2021-25949 Vulnerability in npm package set-getter
CVE-2021-3503 Vulnerability in maven package org.wildfly:wildfly-metrics
CVE-2022-23463 Vulnerability in maven package com.nepxion:discovery-commons