Executive brief
jikes is a JavaScript package used in web development. A directory traversal vulnerability allows attackers to access files outside the intended directory, potentially exposing sensitive system files like passwords and configuration data. No patch is available; the vendor recommends using only in local development.
Technical details
A path traversal vulnerability (CWE-22) exists in jikes due to improper handling of relative file paths. Attackers can craft requests using directory traversal sequences (e.g., "../../") to access arbitrary files on the filesystem outside the intended application root. The vulnerability is exploitable via network requests and requires no authentication. Successful exploitation leads to disclosure of private files; no patch has been released.
Affected products
- npm jikes 0.0.1 and all 0.x versions
Timeline
- 2018-08-06: disclosed
- 2017: advisory: CVE-2017-16139 assigned