Junglewise Threat Intelligence

CVE-2017-16110: weather.swlyons directory traversal

CVE-2017-16110 · Severity: low · CVSS 3 · Published 2020-09-01

Vendors: npm.

Executive brief

weather.swlyons is a simple web server package used for weather updates. A security flaw allows an attacker to bypass folder restrictions and access sensitive files on the host server, such as system configuration files or private data. Because no fix is available, it is recommended to stop using this package in production environments.

Technical details

The weather.swlyons package for Node.js is vulnerable to a directory traversal vulnerability (CWE-22) because it fails to properly sanitize user-supplied input when resolving file paths. An unauthenticated remote attacker can exploit this by sending specially crafted HTTP GET requests containing 'dot-dot-slash' (../) sequences. This allows the attacker to escape the intended web root directory and read arbitrary files on the server's filesystem that the process has permissions to access (e.g., /etc/passwd). As of the latest advisory, no patch is available, and users are advised to migrate to alternative packages.

Affected products

  • weather.swlyons_project weather.swlyons All versions

Timeline

  • 2017-10-30: disclosed: Vulnerability reported via HackerOne
  • 2018-06-06: advisory: NVD published CVE-2017-16110
  • 2020-09-01: advisory: GitHub Advisory GHSA-2r4h-2ghh-5hpx published

References