Record summary

CVE-2018-6184 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

ZEIT Next.js 4 before 4.2.3 has Directory Traversal under the /_next request namespace.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
GitHub Advisory1.0.0 to < 4.2.3 · Fixed in 4.2.3affected

Nuclei templates

1
ProjectDiscoveryHIGHZeit Next.js < 4.2.3 - Local File InclusionCVSS 7.5

Zeit Next.js before 4.2.3 is susceptible to local file inclusion under the /_next request namespace. An attacker can obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site.

Impact

An attacker can exploit this vulnerability to read sensitive files, execute arbitrary code, or launch further attacks.

Remediation

Upgrade to the latest version of Zeit Next.js (>=4.2.3) to mitigate this vulnerability.

WeaknessesCWE-22
AuthorsDhiyaneshDK
Template tagscve2018cvenextjslfitraversalzeitvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:zeit:next.js:4.0.0:*:*:*:*:*:*:*
Shodan: html:"/_next/static"
Shodan: http.html:"/_next/static"
Shodan: cpe:"cpe:2.3:a:zeit:next.js"
FOFA: body="/_next/static"

Source: ProjectDiscovery

References

5