Junglewise Threat Intelligence

CVE-2017-16184: scott-blanch-weather-app directory traversal

CVE-2017-16184 · Severity: low · CVSS 3 · Published 2020-09-01

Vendors: npm.

Executive brief

scott-blanch-weather-app is an npm package for weather data retrieval. An attacker can exploit a directory traversal vulnerability to read arbitrary files on the server, including sensitive configuration files and private data, by manipulating file paths in requests.

Technical details

The vulnerability is a path traversal (CWE-22) flaw in scott-blanch-weather-app where relative file paths are not properly sanitized. An unauthenticated attacker with network access can craft requests using "../" sequences to escape the intended directory root and access arbitrary files on the filesystem. The vulnerability is exploitable without authentication or special preconditions. An attacker can read sensitive files such as /etc/passwd and other private data. No patch is available; the vendor recommends using this package only for local development.

Affected products

  • scott-blanch scott-blanch-weather-app all versions from 0.0.0

Timeline

  • 2020-09-01: disclosed: Published to GitHub Advisory Database

References