Junglewise Threat Intelligence

CVE-2020-36629: SimbCo httpster path traversal

CVE-2020-36629 · Severity: low · CVSS 3.1 · Published 2022-12-25

Vendors: npm.

Executive brief

SimbCo httpster is a lightweight Node.js file server used to quickly serve static files over HTTP. An attacker can exploit a path traversal vulnerability to read files outside the intended directory, potentially exposing sensitive configuration files, source code, or other confidential data stored on the server.

Technical details

The vulnerability exists in the fs.realpathSync function within src/server.coffee and is classified as a path traversal (CWE-22) vulnerability. An unauthenticated attacker with network access can craft HTTP requests containing directory traversal sequences (e.g., ../../../) in the URL path to bypass directory restrictions and access arbitrary files on the server. The vulnerability affects all versions prior to 1.1.0. A patch has been released (commit d3055b3e30b40b65d30c5a06d6e053dffa7f35d0) and users should upgrade to version 1.1.0 or later to remediate the issue.

Affected products

  • SimbCo httpster before 1.1.0

Timeline

  • 2020-09-03: disclosed
  • 2020-11-20: patched: Fix merged in PR #36
  • 2022-12-25: advisory

References