Executive brief
22lixian is a Node.js package that resolves file paths unsafely, allowing attackers to access files outside the intended directory. An unauthenticated attacker can craft malicious requests to read sensitive system files like /etc/passwd, potentially exposing private data on vulnerable systems. There is no patch available for this vulnerability.
Technical details
The vulnerability is a classic directory traversal (CWE-22) resulting from improper handling of relative file paths in the 22lixian package. The vulnerability allows an attacker to use path traversal sequences (../) in HTTP requests to escape the intended directory root and access arbitrary files on the filesystem. The attack vector is network-based with no authentication required and no user interaction needed. An attacker can achieve confidentiality breach by reading sensitive files; no patch has been released and the package should not be used in production.
Affected products
- npm 22lixian up to and including 1.0.0
Timeline
- 2018-07-23: disclosed
- 2017: other: CVE-2017-16162 published