CVE-2017-14849
UnknownEPSS 53.42%
Last modified
CVE-2017-14849 is a vulnerability of currently unknown severity. Node.js 8.5.0 before 8.6.0 allows remote attackers to access unintended files, because a change to ".." handling was incompatible with the pathname validation used by unspecified community modules.. EPSS estimates a 53.42% chance of exploitation in the next 30 days.
Description
Node.js 8.5.0 before 8.6.0 allows remote attackers to access unintended files, because a change to ".." handling was incompatible with the pathname validation used by unspecified community modules.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Nodejs | Node.Js | 8.5.0 |
References
- http://www.securityfocus.com/bid/101056Third Party Advisory, VDB Entry
- https://nodejs.org/en/blog/vulnerability/september-2017-path-validation/Patch, Vendor Advisory
- https://twitter.com/nodejs/status/913131152868876288Patch, Third Party Advisory
- http://www.securityfocus.com/bid/101056Third Party Advisory, VDB Entry
- https://nodejs.org/en/blog/vulnerability/september-2017-path-validation/Patch, Vendor Advisory
- https://twitter.com/nodejs/status/913131152868876288Patch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-14849?
Node.js 8.5.0 before 8.6.0 allows remote attackers to access unintended files, because a change to ".." handling was incompatible with the pathname validation used by unspecified community modules.
How severe is CVE-2017-14849?
Severity scoring for CVE-2017-14849 is pending analysis. The EPSS model estimates a 53.42% probability of exploitation in the next 30 days.
How do I fix CVE-2017-14849?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-14843Mojoomla School Management System for WordPress allows SQL I…
- CVE-2017-14844Mojoomla WPGYM WordPress Gym Management System allows SQL In…
- CVE-2017-14845Mojoomla WPCHURCH Church Management System for WordPress all…
- CVE-2017-14846Mojoomla Hospital Management System for WordPress allows SQL…
- CVE-2017-14847Mojoomla WPAMS Apartment Management System for WordPress all…
- CVE-2017-14848WPHRM Human Resource Management System for WordPress 1.0 all…8.8
- CVE-2017-1485IBM Cognos Analytics 11.0 is vulnerable to cross-site script…
- CVE-2017-14850All known versions of the Orpak SiteOmat web management cons…6.1
- CVE-2017-14851A SQL injection vulnerability exists in all Orpak SiteOmat v…9.8
- CVE-2017-14852An insecure communication was found between a user and the O…8.6
- CVE-2017-14853The Orpak SiteOmat OrCU component is vulnerable to code inje…8.6
- CVE-2017-14854A stack buffer overflow exists in one of the Orpak SiteOmat …9.1
Are you affected by CVE-2017-14849?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
