Junglewise Threat Intelligence

CVE-2023-25345: Node-swig swig-templates directory traversal in include and extends tags

CVE-2023-25345 · Severity: low · CVSS 3.1 · Published 2023-03-15

Vendors: npm.

Executive brief

Swig-templates is a template engine for Node.js used to generate dynamic web content. A security flaw allows an attacker to bypass directory restrictions and read sensitive files from the underlying server, such as configuration files or system credentials. This could lead to the exposure of private data and provide a foothold for further attacks on the infrastructure.

Technical details

A directory traversal vulnerability (CWE-22) exists in swig-templates through version 2.0.4 and the original swig library through version 1.4.2. The vulnerability is rooted in the template rendering engine's failure to properly sanitize file paths provided to the 'include' and 'extends' tags. An attacker can use 'dot-dot-slash' (../) sequences to escape the intended template directory and access sensitive system files (e.g., /etc/passwd). This can be exploited remotely if the application renders templates based on user-controlled input or if an attacker can upload malicious template files. The repository was archived in February 2023, and no official patch has been released.

Affected products

  • node-swig swig-templates <= 2.0.4
  • node-swig swig <= 1.4.2

Timeline

  • 2023-02-01: disclosed: Issue reported on GitHub repository
  • 2023-03-15: advisory: NVD and GHSA advisories published

References