Executive brief
m-server is a lightweight Node.js HTTP server library used to serve files and content. A path traversal vulnerability allows remote attackers to bypass directory restrictions and read arbitrary files from the server's filesystem, potentially exposing sensitive configuration files, source code, or credentials.
Technical details
A path traversal vulnerability (CWE-22) exists in m-server versions before 1.4.2 in the file serving mechanism. The vulnerability allows a remote attacker to craft requests using directory traversal sequences (e.g., "../" or encoded variants) to bypass intended path restrictions and access arbitrary files on the server. No authentication is required as this affects the HTTP request handling layer. An attacker can read sensitive files including configuration, source code, and system files. The fix is available in version 1.4.2 and later.
Affected products
- m-server m-server before 1.4.2
Timeline
- 2019-06-11: disclosed
- 2019-06-11: patched: fix available in version 1.4.2