Junglewise Threat Intelligence

CVE-2017-16208: dmmcquay.lab6 directory traversal

CVE-2017-16208 · Severity: low · CVSS 3 · Published 2020-09-01

Vendors: npm.

Executive brief

dmmcquay.lab6 is a Node.js package used for local development that serves files from a directory. A directory traversal vulnerability allows attackers to bypass access restrictions and read arbitrary files on the system—such as configuration files, credentials, or other sensitive data—by using specially crafted URLs with path traversal sequences (e.g., "../../etc/passwd").

Technical details

The vulnerability is a path traversal (CWE-22) in dmmcquay.lab6 caused by insufficient validation of relative file paths before serving them. An unauthenticated attacker can craft HTTP requests with sequences like "/../" to traverse outside the intended document root and access arbitrary files readable by the application process. No authentication or user interaction is required; exploitation is straightforward via simple HTTP GET requests. The package is affected across all versions from 0.0.0 onwards. No patch has been released; the advisory recommends the package be used only for local development and not in production environments.

Affected products

  • dmmcquay lab6 all versions from 0.0.0

Timeline

  • 2020-09-01: disclosed

References