Executive brief
exxxxxxxxxxx is an npm package used for file serving. The package fails to properly sanitize relative file paths, allowing an attacker to access files outside the intended directory root (such as /etc/passwd) through path traversal attacks. This could expose sensitive system files and private data stored on the server.
Technical details
This is a directory traversal vulnerability (CWE-22) in exxxxxxxxxxx caused by improper resolution of relative file paths. An attacker can craft requests using path traversal sequences (e.g., GET /../../../../../../etc/passwd) to access files outside the intended root directory. The vulnerability is exploitable over the network without authentication, though it is partially mitigated by requiring requests to target files with extensions. No patch is available; affected versions are 1.0.2 and earlier.
Affected products
- exxxxxxxxxxx 1.0.2 and earlier
Timeline
- 2018-07-23: disclosed
- other: CVE assigned as CVE-2017-16130