漏洞描述
Zeit Next.js before 4.2.3 is susceptible to local file inclusion under the /_next request namespace. An attacker can obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
github.comhttps://github.com/PortSwigger/j2ee-scan/blob/master/src/main/java/burp/j2ee/issues/impl/NextFrameworkPathTraversal.java↗github.comhttps://github.com/zeit/next.js/releases/tag/4.2.3↗nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2018-6184↗github.comhttps://github.com/lnick2023/nicenice↗github.comhttps://github.com/masasron/vulnerability-research↗