Junglewise Threat Intelligence

CVE-2017-16222: elding directory traversal vulnerability

CVE-2017-16222 · Severity: low · CVSS 3 · Published 2018-08-06

Vendors: npm.

Executive brief

elding is a Node.js library used for file serving. The library fails to properly sanitize relative file paths, allowing attackers to access files outside the intended directory root through directory traversal attacks (e.g., using ../ sequences). An attacker could read arbitrary files on a system running this library, potentially exposing sensitive configuration or application data.

Technical details

The vulnerability is a classic directory traversal (CWE-22) affecting the elding npm package. The library fails to properly resolve and sanitize relative file paths, allowing attackers to craft HTTP requests with traversal sequences (../) to access files outside the intended root directory. The vulnerability only affects paths that include file extensions (e.g., /../../secrets.json), as the library treats paths without extensions as directories. Network accessibility is required, no authentication is needed, and no user interaction is required. An attacker can read arbitrary files with the application's privileges. No patch is available; the advisory recommends using the package only for local development and switching to alternative solutions for production use.

Affected products

  • npm elding 0 through 1.0.0

Timeline

  • 2018-08-06: disclosed

References