Description
Node-RED-Dashboard before 2.26.2 allows ui_base/js/..%2f directory traversal to read files.
Remediation
References
https://github.com/node-red/node-red-dashboard/issues/669
https://github.com/node-red/node-red-dashboard/releases/tag/2.26.2
Related Vulnerabilities
CVE-2014-7808 Vulnerability in maven package org.apache.wicket:wicket-util
CVE-2019-9212 Vulnerability in maven package com.alipay.sofa:hessian
CVE-2021-29506 Vulnerability in maven package com.graphhopper:graphhopper-nav
CVE-2020-35774 Vulnerability in maven package com.twitter:twitter-server
CVE-2018-1270 Vulnerability in maven package org.springframework:spring-messaging