Lucene search

K
githubGitHub Advisory DatabaseGHSA-4WCH-FWMX-CF47
HistorySep 18, 2018 - 1:50 p.m.

Directory Traversal in augustine

2018-09-1813:50:25
CWE-22
GitHub Advisory Database
github.com
14

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

25.5%

Affected versions of augustine resolve relative file paths, resulting in a directory traversal vulnerability. A malicious actor can use this vulnerability to access files outside of the intended directory root, which may result in the disclosure of private files on the vulnerable system.

Proof of Concept

GET //etc/passwd HTTP/1.1
host:foo

Recommendation

No direct patch is available at this time.

Currently, the best mitigation for this flaw is to use a different, functionally equivalent static file server package.

Affected configurations

Vulners
Node
augustine_projectaugustineRange0.2.3node.js
VendorProductVersionCPE
augustine_projectaugustine*cpe:2.3:a:augustine_project:augustine:*:*:*:*:*:node.js:*:*

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

25.5%

Related for GHSA-4WCH-FWMX-CF47