Junglewise Threat Intelligence

CVE-2017-16144: myserver.alexcthomas18 directory traversal

CVE-2017-16144 · Severity: low · CVSS 3 · Published 2018-07-23

Vendors: npm.

Executive brief

myserver.alexcthomas18 is a Node.js package that serves files over HTTP. The package fails to properly validate file paths, allowing attackers to access files outside the intended directory tree (such as /etc/passwd) without any authentication. This could expose sensitive system files and secrets to an attacker over the network.

Technical details

The vulnerability is a path traversal (CWE-22) flaw where the package resolves relative file paths without proper normalization or bounds checking. An unauthenticated network attacker can craft HTTP GET requests using path traversal sequences (e.g., /../../../) to escape the intended root directory and read arbitrary files on the system. No authentication or user interaction is required. An attacker can disclose private files including application secrets and system configuration. No patch is available; the vendor recommends using the package only for local development or switching to an alternative.

Affected products

  • alexcthomas18 myserver 0.0.1 and earlier

Timeline

  • 2018-07-23: disclosed

References