Junglewise Threat Intelligence

CVE-2017-16162: 22lixian directory traversal

CVE-2017-16162 · Severity: low · CVSS 3 · Published 2018-07-23

Vendors: npm.

Executive brief

22lixian is a Node.js package that resolves file paths unsafely, allowing attackers to access files outside the intended directory. An unauthenticated attacker can craft malicious requests to read sensitive system files like /etc/passwd, potentially exposing private data on vulnerable systems. There is no patch available for this vulnerability.

Technical details

The vulnerability is a classic directory traversal (CWE-22) resulting from improper handling of relative file paths in the 22lixian package. The vulnerability allows an attacker to use path traversal sequences (../) in HTTP requests to escape the intended directory root and access arbitrary files on the filesystem. The attack vector is network-based with no authentication required and no user interaction needed. An attacker can achieve confidentiality breach by reading sensitive files; no patch has been released and the package should not be used in production.

Affected products

  • npm 22lixian up to and including 1.0.0

Timeline

  • 2018-07-23: disclosed
  • 2017: other: CVE-2017-16162 published

References