Executive brief
inert is a Node.js library used to serve static files in web applications. The vulnerability allows attackers to access files in hidden directories even when the application is configured to hide them, potentially exposing sensitive configuration files or private data that the developer intended to keep hidden from users.
Technical details
The vulnerability is a path traversal/directory traversal issue (CWE-22) in inert versions 1.1.1 and earlier. The inert static file handler does not properly enforce the showHidden=false configuration setting, allowing files within hidden directories (directories starting with a dot) to be served to clients. An attacker can request files from hidden directories via direct HTTP requests without authentication. The fix was merged in December 2014 and released in version 1.1.1 or later.
Affected products
- hapijs inert 1.1.1 and earlier
Timeline
- 2020-08-31: disclosed
- 2014-12-04: patched: Fix merged in PR #15