Junglewise Threat Intelligence

CVE-2017-16179: dasafio directory traversal vulnerability

CVE-2017-16179 · Severity: low · CVSS 3 · Published 2020-09-01

Vendors: npm.

Executive brief

dasafio is a Node.js package commonly used for local development and file serving. The package fails to properly sanitize relative file paths, allowing attackers to access files outside the intended application directory, including sensitive system files like /etc/passwd. This vulnerability could expose private configuration files, source code, or other sensitive data on affected systems.

Technical details

The vulnerability is a classic directory traversal (CWE-22) weakness in path resolution. dasafio does not properly validate or canonicalize relative file paths before resolving them, allowing sequences like "../" to escape the intended root directory. The attack is network-reachable with no authentication or user interaction required; an attacker can craft HTTP requests with traversal payloads (e.g., GET /../../../../../../etc/passwd) to read arbitrary files accessible to the process. No patch has been released; the vendor recommends restricting dasafio to local development use only and switching to alternative packages if production file serving is required.

Affected products

  • dasafio dasafio 0.0.0 and later (no patch available)

Timeline

  • 2017: disclosed: CVE-2017-16179 originally assigned
  • 2020-09-01: advisory: GHSA-8xj3-7258-w4q2 published

References