Executive brief
jn_jj_server is a Node.js package used as a local development server. It contains a directory traversal vulnerability that allows attackers to read files outside the intended directory root, potentially exposing sensitive system files like /etc/passwd. An attacker can craft malicious HTTP requests with path traversal sequences (e.g., ../../) to access private data on the vulnerable system.
Technical details
The vulnerability is a path traversal flaw (CWE-22) in jn_jj_server's file resolution logic. The server fails to properly sanitize or validate relative file paths in HTTP requests, allowing attackers to traverse the directory tree using sequences like /../ to escape the intended root directory. The attack is network-accessible and requires no authentication. An attacker can read arbitrary files accessible to the process, such as configuration files or system files. No patch is available; the advisory recommends limiting use to local development only and substituting an alternative package for production deployments.
Affected products
- npm jn_jj_server 0.0.8 and earlier
Timeline
- 2018-07-23: disclosed: Advisory published on GitHub Advisory Database
- 2017: other: CVE-2017-16210 assigned