Junglewise Threat Intelligence

CVE-2017-16139: jikes directory traversal vulnerability

CVE-2017-16139 · Severity: info · Published 2018-08-06

Vendors: npm.

Executive brief

jikes is a JavaScript package used in web development. A directory traversal vulnerability allows attackers to access files outside the intended directory, potentially exposing sensitive system files like passwords and configuration data. No patch is available; the vendor recommends using only in local development.

Technical details

A path traversal vulnerability (CWE-22) exists in jikes due to improper handling of relative file paths. Attackers can craft requests using directory traversal sequences (e.g., "../../") to access arbitrary files on the filesystem outside the intended application root. The vulnerability is exploitable via network requests and requires no authentication. Successful exploitation leads to disclosure of private files; no patch has been released.

Affected products

  • npm jikes 0.0.1 and all 0.x versions

Timeline

  • 2018-08-06: disclosed
  • 2017: advisory: CVE-2017-16139 assigned

References