Junglewise Threat Intelligence

CVE-2017-16175: ewgaddis.lab6 directory traversal

CVE-2017-16175 · Severity: low · CVSS 3 · Published 2018-07-23

Vendors: npm.

Executive brief

ewgaddis.lab6 is a Node.js library that fails to properly validate file paths, allowing attackers to read arbitrary files outside the intended directory. An unauthenticated attacker can craft a simple HTTP request with path traversal sequences (e.g., `/../../../etc/passwd`) to access sensitive files on the system, potentially exposing configuration data, private keys, or other confidential information.

Technical details

ewgaddis.lab6 contains a path traversal vulnerability (CWE-22) where relative file paths are resolved without proper normalization or restriction to a base directory. The vulnerability is accessible via network requests containing relative path sequences (e.g., `GET /../../../../../../etc/passwd`). No authentication or user interaction is required; the attack surface is exposed to any network-accessible instance. An attacker can read arbitrary files accessible to the process, leading to information disclosure of sensitive data. No patch has been released; the package maintainers recommend using it only for local development and substituting an alternative package for production use.

Affected products

  • ewgaddis lab6 <= 0.1.1

Timeline

  • 2018-07-23: disclosed: Published to GitHub Advisory Database

References