Junglewise Threat Intelligence

CVE-2017-16096: serveryaozeyan directory traversal

CVE-2017-16096 · Severity: low · CVSS 3 · Published 2020-09-01

Vendors: npm.

Executive brief

serveryaozeyan is a Node.js development server package. The vulnerability allows attackers to access files outside the intended web root directory by crafting malicious requests with path traversal sequences (e.g., "../../"), potentially exposing sensitive system files and private data on affected servers.

Technical details

The vulnerability is a classic directory traversal (CWE-22) flaw in serveryaozeyan's file path resolution logic. The server fails to properly sanitize or validate relative file paths in HTTP requests, allowing attackers to traverse parent directories using "../" sequences. The attack requires network access to the server and no authentication; an attacker can craft a GET request like "GET /../../../../../../etc/passwd" to read arbitrary files. This results in confidentiality impact through unauthorized file disclosure. No patch is available; the advisory recommends using the package only for local development and switching to alternatives if production deployment is required.

Affected products

  • npm serveryaozeyan all versions

Timeline

  • 2020-09-01: disclosed

References