Junglewise Threat Intelligence

CVE-2022-21192: serve-lite directory traversal in file serving

CVE-2022-21192 · Severity: low · CVSS 3.1 · Published 2023-01-26

Vendors: npm.

Executive brief

serve-lite is a lightweight HTTP server used to serve static web files during development. An attacker can exploit a directory traversal vulnerability to bypass restrictions and access files stored outside the intended serving directory, such as private keys, configuration files, and source code. This allows unauthorized access to sensitive information on the server. The vulnerability affects all released versions up to 1.1.0 and has been patched in version 1.1.1.

Technical details

serve-lite is vulnerable to CWE-22 (Path Traversal) due to missing input validation on the req.url parameter. The vulnerability exists in server.js lines 111–114, where req.url is decoded and passed directly to path.join() without sanitization, allowing attackers to inject path traversal sequences (../) to escape the configured root directory. The attack is network-accessible, requires no authentication or user interaction, and allows complete information disclosure of any file readable by the server process. An attacker can craft requests like http://localhost:3000/../../../etc/passwd to read arbitrary files. The vulnerability is fixed in version 1.1.1 (commit ba3efb7) with proper input validation.

Affected products

  • serve-lite serve-lite 0 to 1.1.0

Timeline

  • 2022-11-28: disclosed
  • 2023-01-26: advisory
  • 2023-05-02: patched: Version 1.1.1 released with fix

References

Related threats