Executive brief
360class.jansenhm is a static file server used to deliver web content. A security flaw allows unauthorized users to bypass folder restrictions and access sensitive files on the underlying server, such as configuration files or system passwords. This could lead to the exposure of private data and compromise the security of the entire hosting environment.
Technical details
The 360class.jansenhm package fails to properly sanitize user-supplied input in file paths, leading to a directory traversal vulnerability (CWE-22). By using dot-dot-slash (../) sequences in a URL request, an unauthenticated remote attacker can escape the intended web root directory. This allows for the retrieval of sensitive system files, such as /etc/passwd, provided the process has sufficient permissions. No patch is currently available, and users are advised to migrate to a different package for production environments.
Affected products
- jansenhm 360class.jansenhm All versions
Timeline
- 2017-11-01: disclosed: Initial discovery/CVE assignment
- 2018-06-06: advisory: NVD publication date
- 2020-09-01: advisory: GitHub Advisory published