Vulnerability Description
ZEIT Next.js before 2.4.1 has directory traversal under the /_next and /static request namespace, allowing attackers to obtain sensitive information.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zeit | Next.Js | < 2.4.1 |
Related Weaknesses (CWE)
References
- https://github.com/vercel/next.js/commit/02fe7cf63f6265d73bdaf8bc50a4f2fb539dcd0
- https://github.com/zeit/next.js/releases/tag/2.4.1Third Party Advisory
- https://github.com/vercel/next.js/commit/02fe7cf63f6265d73bdaf8bc50a4f2fb539dcd0
- https://github.com/zeit/next.js/releases/tag/2.4.1Third Party Advisory
FAQ
What is CVE-2017-16877?
CVE-2017-16877 is a vulnerability with a CVSS score of 7.5 (HIGH). ZEIT Next.js before 2.4.1 has directory traversal under the /_next and /static request namespace, allowing attackers to obtain sensitive information.
How severe is CVE-2017-16877?
CVE-2017-16877 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-16877?
Check the references section above for vendor advisories and patch information. Affected products include: Zeit Next.Js.