Junglewise Threat Intelligence

CVE-2017-16038: f2e-server directory traversal vulnerability

CVE-2017-16038 · Severity: low · CVSS 3 · Published 2018-07-24

Vendors: npm.

Executive brief

f2e-server is a Node.js package that serves static files and provides development server functionality. The package fails to properly validate file path requests, allowing an attacker to traverse directories and read arbitrary files outside the intended serving directory (such as /etc/passwd). This exposes sensitive configuration files and private data stored on the server.

Technical details

This is a directory traversal (path traversal) vulnerability in the f2e-server package that stems from insufficient validation of relative file paths in HTTP requests. The vulnerability is triggered by relative path sequences (e.g., /../../../) in request URLs, which are resolved without proper sanitization. An unauthenticated attacker on the network can craft HTTP GET requests containing traversal sequences to access files outside the intended document root, potentially disclosing private files and configuration data. The vulnerability affects all versions prior to 1.12.12, which introduced proper path filtering to prevent traversal attacks.

Affected products

  • f2e-server f2e-server < 1.12.12

Timeline

  • 2017-04-18: disclosed: Issue reported on GitHub
  • 2018-07-24: advisory: GHSA advisory published
  • 2017: patched: Fixed in version 1.12.12

References