Junglewise Threat Intelligence

CVE-2019-15600: http_server cross-site scripting via unsanitized filenames

CVE-2019-15600 · Severity: low · CVSS 3.1 · Published 2020-03-31

Technologies: Http-Server Community HTTP Server.

Executive brief

http_server is a lightweight Node.js web server package commonly used for serving static files and prototyping. The vulnerability allows attackers to inject arbitrary JavaScript code through maliciously-named files, which executes in the browsers of users who access the server. An attacker can use this to steal session tokens, redirect users, or perform actions on behalf of legitimate users.

Technical details

http_server contains a cross-site scripting (XSS) vulnerability (CWE-22, Path Traversal/Improper Neutralization) caused by failure to sanitize or encode filenames in directory listings and responses. The vulnerability affects all versions up to and including 1.0.12. An attacker can create files with names containing JavaScript code (e.g., <img src=x onerror=alert('xss')>), and when a victim visits the server's directory listing or requests the file, the unsanitized filename is reflected in the HTML response without proper encoding, causing the JavaScript to execute in the victim's browser. The attack requires network access to the http_server instance and user interaction (visiting a link), but no authentication. No patch is currently available; users are recommended to migrate to alternative packages.

Affected products

  • http-server community http_server all versions up to 1.0.12

Timeline

  • 2019: disclosed: vulnerability reported via HackerOne
  • 2020-03-31: advisory: GHSA-754x-4jwp-cqp6 published

References