Junglewise Threat Intelligence

CVE-2017-16095: serverliujiayi1 directory traversal vulnerability

CVE-2017-16095 · Severity: low · CVSS 3 · Published 2020-09-01

Vendors: npm.

Executive brief

serverliujiayi1 is a Node.js package that fails to properly validate file paths, allowing attackers to read arbitrary files from the server by using directory traversal sequences like "../" in requests. An attacker can exploit this to access sensitive system files such as configuration files or credentials, potentially leading to data exposure and further compromise of the affected system.

Technical details

The vulnerability is a directory traversal (path traversal) flaw in serverliujiayi1's file resolution logic. The package does not properly sanitize or validate relative file paths, allowing attackers to use sequences like "../../" to escape the intended directory root and access files outside the designated serving directory. The attack is network-accessible, requires no authentication or user interaction, and can be exploited via simple HTTP GET requests (e.g., GET /../../../../../../etc/passwd). An attacker can disclose arbitrary files readable by the server process. No patch is available; the vendor recommends the package be used only for local development, and production deployments should switch to an alternative package.

Affected products

  • serverliujiayi1 serverliujiayi1 0.0.0 and later

Timeline

  • 2020-09-01: disclosed
  • other: CVE-2017-16095 published (disclosure date predates advisory publication)

References