Junglewise Threat Intelligence

CVE-2014-10068: inert path traversal allows access to hidden directories

CVE-2014-10068 · Severity: info · Published 2020-08-31

Vendors: Hapi.

Executive brief

inert is a Node.js library used to serve static files in web applications. The vulnerability allows attackers to access files in hidden directories even when the application is configured to hide them, potentially exposing sensitive configuration files or private data that the developer intended to keep hidden from users.

Technical details

The vulnerability is a path traversal/directory traversal issue (CWE-22) in inert versions 1.1.1 and earlier. The inert static file handler does not properly enforce the showHidden=false configuration setting, allowing files within hidden directories (directories starting with a dot) to be served to clients. An attacker can request files from hidden directories via direct HTTP requests without authentication. The fix was merged in December 2014 and released in version 1.1.1 or later.

Affected products

  • hapijs inert 1.1.1 and earlier

Timeline

  • 2020-08-31: disclosed
  • 2014-12-04: patched: Fix merged in PR #15

References