Junglewise Threat Intelligence

CVE-2017-18355: Google Rendertron information disclosure of absolute file paths

CVE-2017-18355 · Severity: low · CVSS 3 · Published 2019-02-12

Technologies: rendertron (npm). Vendors: Google, npm.

Executive brief

Rendertron is a headless Chrome rendering service used to pre-render web applications for search engines and crawlers. The vulnerability allows unauthenticated remote attackers to discover the absolute file paths of installed Node.js packages by reading metadata exposed in the node_modules directory, potentially revealing sensitive deployment and infrastructure information that could aid in further attacks.

Technical details

Rendertron versions prior to 1.1.0 expose the node_modules directory and package metadata over the network, allowing attackers to read the "_where" attribute in package.json files. This CWE-200 information disclosure vulnerability is network-accessible with no authentication or user interaction required. An attacker can craft requests to retrieve package.json files from installed dependencies, revealing absolute file paths on the server that disclose the application's directory structure and deployment configuration. The vulnerability was fixed in version 1.1.0 by removing or restricting access to sensitive package metadata.

Affected products

  • Google Rendertron before 1.1.0

Timeline

  • 2019-02-12: disclosed
  • 2017-08-30: patched: Fix merged to master branch; version 1.1.0 released with patch

References

Related threats