Node.js 8.5.0 gater than equal and less than 8.6.0 Directory Traversal

Published on 01 Oct 2021
Vulnerability

Node.js 8.5.0 before 8.6.0 allows remote attackers to access unintended files. The reason is that Node.js 8.5.0 has a logic error when performing the normalize operation on the directory, which leads to the jump to the upper level(such as ../../../foo/../../../../etc/passwd).

Impact:

This logic error causes the normalize function to return an error result, bypassing the check, and causing arbitrary file reading vulnerabilities.

Mitigation / Precaution

In order to patch this vulnerability, we suggest you to upgrade Node js to the latest version.

Rejah Rehim
Written by
Co-founder, Director

Rejah brings more than 12 years of industry experience in Information Technology. He is a fervent security enthusiast and serves as a Project Leader at OWASP Foundation, and Commander (Hon.) at Kerala Police. He has authored two books titled “Effective Python Penetration Testing” and “Python Penetration Testing Cookbook” and is the creator of 9 Mozilla add-ons.

Experience the Beagle Security platform
Unlock one full penetration test and all Advanced plan features free for 14 days
4.8 on G2 • ISO 27001 certified
See How Beagle Security Works
No credit card • No setup required
Launch interactive demo