Description
node-red-contrib-huemagic 3.0.0 is affected by hue/assets/..%2F Directory Traversal.in the res.sendFile API, used in file hue-magic.js, to fetch an arbitrary file.
Remediation
References
https://github.com/Foddy/node-red-contrib-huemagic/issues/217
Related Vulnerabilities
CVE-2020-35214 Vulnerability in maven package io.atomix:atomix
CVE-2023-36820 Vulnerability in maven package io.micronaut.security:micronaut-security-oauth2
CVE-2022-21700 Vulnerability in maven package io.micronaut:micronaut-http
CVE-2016-8749 Vulnerability in maven package org.apache.camel:camel-jacksonxml
CVE-2020-7752 Vulnerability in npm package systeminformation