Junglewise Threat Intelligence

CVE-2021-30483: isomorphic-git directory traversal via malicious file paths

CVE-2021-30483 · Severity: low · CVSS 3.1 · Published 2021-09-02

Vendors: npm.

Executive brief

isomorphic-git is a JavaScript library that allows developers to work with Git repositories in the browser and Node.js environments. A directory traversal vulnerability allows attackers to write files outside the intended repository directory by crafting a malicious Git repository with specially crafted file paths. This could lead to unauthorized file creation or modification on the system running the application.

Technical details

isomorphic-git before version 1.8.2 is vulnerable to directory traversal (CWE-22) through malicious file paths embedded in a Git repository structure. The vulnerability occurs in the checkout functionality when parsing Git trees without sufficient validation of file paths, allowing use of path traversal sequences (e.g., "../"). An attacker can craft a malicious repository that, when checked out by a victim application, writes files to arbitrary locations on the filesystem. The fix, merged in PR #1339, introduces an UnsafeFilepathError that is thrown when detecting malicious paths during Git tree parsing. The vulnerability requires the victim to clone or checkout a malicious repository but does not require authentication or user interaction beyond the checkout operation itself.

Affected products

  • isomorphic-git isomorphic-git before 1.8.2

Timeline

  • 2021-07-30: disclosed
  • 2021-09-02: advisory
  • 2021-04-12: patched: PR #1339 merged with fix

References