Junglewise Threat Intelligence

CVE-2017-16210: jn_jj_server directory traversal

CVE-2017-16210 · Severity: info · Published 2018-07-23

Vendors: npm.

Executive brief

jn_jj_server is a Node.js package used as a local development server. It contains a directory traversal vulnerability that allows attackers to read files outside the intended directory root, potentially exposing sensitive system files like /etc/passwd. An attacker can craft malicious HTTP requests with path traversal sequences (e.g., ../../) to access private data on the vulnerable system.

Technical details

The vulnerability is a path traversal flaw (CWE-22) in jn_jj_server's file resolution logic. The server fails to properly sanitize or validate relative file paths in HTTP requests, allowing attackers to traverse the directory tree using sequences like /../ to escape the intended root directory. The attack is network-accessible and requires no authentication. An attacker can read arbitrary files accessible to the process, such as configuration files or system files. No patch is available; the advisory recommends limiting use to local development only and substituting an alternative package for production deployments.

Affected products

  • npm jn_jj_server 0.0.8 and earlier

Timeline

  • 2018-07-23: disclosed: Advisory published on GitHub Advisory Database
  • 2017: other: CVE-2017-16210 assigned

References