Executive brief
The getcityapi.yoehoehne npm package is a library for accessing city API data. It contains a directory traversal flaw that allows attackers to read arbitrary files from the server by crafting specially-crafted URLs with path sequences like "../../". This could expose sensitive system files, configuration data, or private application files, resulting in data compromise without any authentication required.
Technical details
This vulnerability is a classic path traversal (CWE-22) issue in the getcityapi.yoehoehne npm package. The root cause is improper neutralization of special path elements (such as "../") when resolving file paths from user-controlled input. An unauthenticated attacker on the network can send HTTP requests with traversal sequences (e.g., GET /../../../../../../etc/passwd) to access files outside the intended directory root. The vulnerability requires no authentication, user interaction, or special privileges. No patch has been released for this vulnerability; the package maintainers recommend using it only for local development and switching to an alternative package for production use.
Affected products
- yoehoehne getcityapi.yoehoehne 0.0.1 and earlier
Timeline
- 2018-07-23: disclosed