Executive brief
statichttpserver is a Node.js package used to serve static files over HTTP. A security flaw allows unauthorized users to bypass directory restrictions and view files on the host server that should not be accessible. This could lead to the exposure of sensitive system files or configuration data, potentially compromising the security of the entire server.
Technical details
A path traversal vulnerability (CWE-22) exists in the statichttpserver npm module due to insufficient sanitization of requested URLs. By using relative path sequences (e.g., '../'), a remote, unauthenticated attacker can escape the designated public directory and access or list arbitrary files on the underlying file system. The vulnerability affects all versions up to and including 0.9.7. As of the advisory date, no official patch has been released, and users are advised to migrate to alternative static file serving packages.
Affected products
- statichttpserver_project statichttpserver <= 0.9.7
Timeline
- 2019-09-03: advisory: NVD published CVE-2019-5480
- 2019-09-04: disclosed: GitHub Advisory GHSA-2j5x-56p6-hj6x published