Vulnerability Description
Node.js 8.5.0 before 8.6.0 allows remote attackers to access unintended files, because a change to ".." handling was incompatible with the pathname validation used by unspecified community modules.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nodejs | Node.Js | 8.5.0 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/101056Third Party AdvisoryVDB Entry
- https://nodejs.org/en/blog/vulnerability/september-2017-path-validation/PatchVendor Advisory
- https://twitter.com/nodejs/status/913131152868876288PatchThird Party Advisory
- http://www.securityfocus.com/bid/101056Third Party AdvisoryVDB Entry
- https://nodejs.org/en/blog/vulnerability/september-2017-path-validation/PatchVendor Advisory
- https://twitter.com/nodejs/status/913131152868876288PatchThird Party Advisory
FAQ
What is CVE-2017-14849?
CVE-2017-14849 is a vulnerability with a CVSS score of 7.5 (HIGH). Node.js 8.5.0 before 8.6.0 allows remote attackers to access unintended files, because a change to ".." handling was incompatible with the pathname validation used by unspecified community modules.
How severe is CVE-2017-14849?
CVE-2017-14849 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-14849?
Check the references section above for vendor advisories and patch information. Affected products include: Nodejs Node.Js.