漏洞描述
Geddy prior to version 13.0.8 contains a directory traversal vulnerability in lib/app/index.js that allows remote attackers to read arbitrary files via a ..%2f (dot dot encoded slash) in the PATH_INFO to the default URI.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
nodesecurity.iohttps://nodesecurity.io/advisories/geddy-directory-traversal↗github.comhttps://github.com/geddy/geddy/issues/697↗github.comhttps://github.com/geddy/geddy/commit/2de63b68b3aa6c08848f261ace550a37959ef231↗nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2015-5688↗github.comhttps://github.com/geddy/geddy/pull/699↗