Executive brief
Total.js is a popular Node.js framework used for building web applications and real-time services. A security flaw in how the framework handles web addresses allows unauthorized users to access files on the server that should be restricted. This could lead to the exposure of sensitive application data, configuration files, or source code, potentially compromising the security of the entire web platform.
Technical details
A path traversal vulnerability exists in total.js (specifically within index.js) due to insufficient sanitization of URL pathnames. An unauthenticated remote attacker can use relative path sequences (e.g., '../') or URL-encoded equivalents (e.g., '%2e%2e%2f') to bypass directory restrictions and access files outside the '/public' folder. While the exploit is limited to specific file extensions (such as .js, .json, .txt, and .xml), it still allows for significant information disclosure. The issue was addressed by improving the validation logic in the request handling component to detect and block these sequences. Fixes are available in version 3.2.3 and various backported patches for older major versions.
Affected products
- Total.js total.js < 3.2.3
Timeline
- 2019-02-18: advisory: NVD published CVE-2019-8903
- 2019-02-20: advisory: GitHub Advisory GHSA-3q32-j57w-q4w7 published
- 2019-02-18: patched: Fixes committed to totaljs/framework repository
References
- https://github.com/totaljs/framework/commit/c37cafbf3e379a98db71c1125533d1e8d5b5aef7
- https://github.com/totaljs/framework/commit/de16238d13848149f5d1dae51f54e397a525932b
- https://blog.certimetergroup.com/it/articolo/security/total.js-directory-traversal-cve-2019-8903
- https://github.com/totaljs/framework
- https://www.npmjs.com/advisories/1026