Junglewise Threat Intelligence

CVE-2018-3809: serve information exposure on case insensitive file systems

CVE-2018-3809 · Severity: low · CVSS 3 · Published 2018-07-18

Technologies: serve (npm). Vendors: npm.

Executive brief

serve is a popular Node.js package for serving static files over HTTP. On case-insensitive file systems (common on Windows and macOS), the package fails to properly enforce file access restrictions, allowing attackers to bypass security controls and access files that should be hidden or ignored.

Technical details

The vulnerability exists in serve versions before 7.0.0 and is rooted in a case-sensitivity bypass in the file access control logic. On case-insensitive file systems (such as NTFS and HFS+), an attacker can request files using alternate casing to circumvent the ignore security control that is intended to block access to sensitive files. The attack requires only network access to the serve HTTP endpoint and no authentication. An attacker can read file contents that should be restricted, leading to information disclosure. The fix is available in serve version 7.0.0 and later.

Affected products

  • npm serve before 7.0.0

Timeline

  • 2018-07-18: disclosed

References

Related threats