Junglewise Threat Intelligence

CVE-2017-16084: list-n-stream directory traversal

CVE-2017-16084 · Severity: info · CVSS 7.5 · Published 2018-07-24

Vendors: npm.

Executive brief

list-n-stream is a static file server used to list and stream local video files. A security flaw allows an attacker to bypass folder restrictions and access any file on the host system. This could lead to the theft of sensitive information, such as system passwords or private configuration files, potentially compromising the entire server.

Technical details

The list-n-stream package is vulnerable to a directory traversal attack (CWE-22) due to improper validation of relative file paths in incoming HTTP requests. By using dot-dot-slash (../) sequences in the URL, a remote, unauthenticated attacker can escape the intended web root directory. This allows for the retrieval of arbitrary files from the underlying filesystem that the Node.js process has permissions to read. The vulnerability is confirmed in versions up to and including 0.0.10 and is addressed in version 0.0.11.

Affected products

  • list-n-stream project list-n-stream <= 0.0.10

Timeline

  • 2018-06-06: advisory: NVD published CVE-2017-16084
  • 2018-07-24: disclosed: GitHub Advisory published

References

Related threats