Executive brief
list-n-stream is a static file server used to list and stream local video files. A security flaw allows an attacker to bypass folder restrictions and access any file on the host system. This could lead to the theft of sensitive information, such as system passwords or private configuration files, potentially compromising the entire server.
Technical details
The list-n-stream package is vulnerable to a directory traversal attack (CWE-22) due to improper validation of relative file paths in incoming HTTP requests. By using dot-dot-slash (../) sequences in the URL, a remote, unauthenticated attacker can escape the intended web root directory. This allows for the retrieval of arbitrary files from the underlying filesystem that the Node.js process has permissions to read. The vulnerability is confirmed in versions up to and including 0.0.10 and is addressed in version 0.0.11.
Affected products
- list-n-stream project list-n-stream <= 0.0.10
Timeline
- 2018-06-06: advisory: NVD published CVE-2017-16084
- 2018-07-24: disclosed: GitHub Advisory published