Junglewise Threat Intelligence

CVE-2017-16142: infraserver directory traversal

CVE-2017-16142 · Severity: low · CVSS 3 · Published 2018-07-23

Vendors: npm.

Executive brief

infraserver is a Node.js package used to serve static files locally during development. A directory traversal flaw allows attackers to read arbitrary files on the system by crafting requests with path traversal sequences (e.g., `/../../../etc/passwd`), potentially exposing sensitive configuration files, credentials, or private data without authentication.

Technical details

The vulnerability is a classic directory traversal (CWE-22) in path resolution logic. infraserver fails to properly sanitize or validate relative file paths in HTTP requests, allowing attackers to traverse outside the intended document root using sequences like `../`. An unauthenticated, network-accessible attacker can send a specially crafted GET request to read arbitrary files readable by the process. No patch is available; the vendor recommends restricting use to local development only.

Affected products

  • npm infraserver 0.0.1 and earlier

Timeline

  • 2018-07-23: disclosed

References