Junglewise Threat Intelligence

CVE-2021-21298: Node-RED path traversal in Projects API

CVE-2021-21298 · Severity: info · Published 2021-02-26

Vendors: Node-RED, npm.

Executive brief

Node-RED is a visual programming tool used for IoT and data flow automation. A path traversal vulnerability in the Projects API allows users with read permissions to access arbitrary files on the server, potentially exposing sensitive configuration, credentials, or application data. This only affects instances where the Projects feature is explicitly enabled.

Technical details

The vulnerability is a path traversal flaw (CWE-22) in the Projects API component of Node-RED. A user with projects.read permission can craft requests to traverse the filesystem and read any file accessible to the Node-RED process. The attack requires the Projects feature to be enabled and the attacker to have read permissions in the Node-RED editor. The fix was patched in Node-RED version 1.2.8. The Projects feature is disabled by default, limiting exposure.

Affected products

  • Node-RED Node-RED before 1.2.8

Timeline

  • 2021-02-19: disclosed
  • 2021-02-26: patched: Version 1.2.8 released

References

Related threats