Junglewise Threat Intelligence

CVE-2017-16130: exxxxxxxxxxx directory traversal vulnerability

CVE-2017-16130 · Severity: low · CVSS 3 · Published 2018-07-23

Vendors: npm.

Executive brief

exxxxxxxxxxx is an npm package used for file serving. The package fails to properly sanitize relative file paths, allowing an attacker to access files outside the intended directory root (such as /etc/passwd) through path traversal attacks. This could expose sensitive system files and private data stored on the server.

Technical details

This is a directory traversal vulnerability (CWE-22) in exxxxxxxxxxx caused by improper resolution of relative file paths. An attacker can craft requests using path traversal sequences (e.g., GET /../../../../../../etc/passwd) to access files outside the intended root directory. The vulnerability is exploitable over the network without authentication, though it is partially mitigated by requiring requests to target files with extensions. No patch is available; affected versions are 1.0.2 and earlier.

Affected products

  • exxxxxxxxxxx 1.0.2 and earlier

Timeline

  • 2018-07-23: disclosed
  • other: CVE assigned as CVE-2017-16130

References