Executive brief
weather.swlyons is a simple web server package used for weather updates. A security flaw allows an attacker to bypass folder restrictions and access sensitive files on the host server, such as system configuration files or private data. Because no fix is available, it is recommended to stop using this package in production environments.
Technical details
The weather.swlyons package for Node.js is vulnerable to a directory traversal vulnerability (CWE-22) because it fails to properly sanitize user-supplied input when resolving file paths. An unauthenticated remote attacker can exploit this by sending specially crafted HTTP GET requests containing 'dot-dot-slash' (../) sequences. This allows the attacker to escape the intended web root directory and read arbitrary files on the server's filesystem that the process has permissions to access (e.g., /etc/passwd). As of the latest advisory, no patch is available, and users are advised to migrate to alternative packages.
Affected products
- weather.swlyons_project weather.swlyons All versions
Timeline
- 2017-10-30: disclosed: Vulnerability reported via HackerOne
- 2018-06-06: advisory: NVD published CVE-2017-16110
- 2020-09-01: advisory: GitHub Advisory GHSA-2r4h-2ghh-5hpx published