Record summary

CVE-2017-16877 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

ZEIT Next.js before 2.4.1 has directory traversal under the /_next and /static request namespace, allowing attackers to obtain sensitive information.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
GitHub Advisory1.0.0 to < 2.4.1 · Fixed in 2.4.1affected

Nuclei templates

1
ProjectDiscoveryHIGHNextjs <2.4.1 - Local File InclusionCVSS 7.5

ZEIT Next.js before 2.4.1 is susceptible to local file inclusion via the /_next and /static request namespace, allowing attackers to obtain sensitive information.

Impact

Successful exploitation of this vulnerability could allow an attacker to read sensitive files on the server, leading to unauthorized access and potential data leakage.

Remediation

Upgrade Nextjs to version 2.4.1 or above to mitigate this vulnerability.

WeaknessesCWE-22
Authorspikpikcu
Template tagscvecve2017nextjslfitraversalzeitvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:zeit:next.js:*:*:*:*:*:*:*:*
Shodan: http.html:"/_next/static"
Shodan: cpe:"cpe:2.3:a:zeit:next.js"
FOFA: body="/_next/static"

Source: ProjectDiscovery

References

4