Executive brief
web-node-server is a Node.js-based web server used for domain name resolution and routing. A security flaw allows unauthorized users to access sensitive files on the server's host system by manipulating URL paths. This could lead to the exposure of private configuration files, system credentials, or other internal data, potentially compromising the entire server environment.
Technical details
A path traversal vulnerability exists in the nodeserver.js file of the web-node-server package. The application fails to properly sanitize user-supplied input in the request URL, allowing an attacker to use '../' sequences to escape the intended web root directory. By sending a crafted HTTP request, an unauthenticated remote attacker can read sensitive files (such as /etc/passwd) that the Node.js process has permissions to access. The issue was addressed by implementing a regex-based sanitization filter to remove '..' sequences from the requested path. The fix is available in version 0.0.11.
Affected products
- youngerheart web-node-server < 0.0.11
Timeline
- 2020-08-22: other: Fix developed and submitted via huntr.dev
- 2020-09-16: patched: Patch merged into master branch
- 2023-01-18: disclosed: Public advisory and CVE assignment