Description
curlrequest through 1.0.1 allows reading any file by populating the file parameter with user input.
Remediation
References
https://snyk.io/vuln/SNYK-JS-CURLREQUEST-568274
https://github.com/node-js-libs/curlrequest/blob/master/index.js#L239%2C
Related Vulnerabilities
CVE-2023-27564 Vulnerability in npm package n8n
CVE-2023-45857 Vulnerability in npm package axios
CVE-2022-35948 Vulnerability in maven package org.webjars.npm:undici
CVE-2022-36883 Vulnerability in maven package org.jenkins-ci.plugins:git
CVE-2021-31404 Vulnerability in maven package com.vaadin:flow-server