Junglewise Threat Intelligence

CVE-2017-16108: gaoxiaotingtingting directory traversal

CVE-2017-16108 · Severity: info · CVSS 7.5 · Published 2020-09-01

Vendors: npm.

Executive brief

gaoxiaotingtingting is a Node.js package used to serve static HTML files. A directory traversal vulnerability allows attackers to access files outside the intended directory root by crafting malicious requests with path traversal sequences (e.g., ../../), potentially exposing sensitive system files like password files or private configuration data.

Technical details

This is a classic directory traversal vulnerability (CWE-22) in the gaoxiaotingtingting npm package. The package fails to properly sanitize or validate relative file paths before resolving them, allowing attackers to use path traversal sequences (e.g., ../../) in HTTP requests to navigate outside the intended web root. The vulnerability requires network access but no authentication. An attacker can read arbitrary files accessible to the application process, such as /etc/passwd or private configuration files. No patch has been released; the recommendation is to use the package only for local development and replace it with an alternative for production use.

Affected products

  • npm gaoxiaotingtingting 0.0.0 and above

Timeline

  • 2017: disclosed: CVE-2017-16108 assigned
  • 2020-09-01: advisory: GHSA-qhf6-vqq9-q2p7 published

References