github.com
https://github.com/advisories/GHSA-m34x-wgrh-g897 CVE-2018-6184
HIGHNuclei
Directory traversal vulnerability in Next.js
Record summary
CVE-2018-6184 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
ZEIT Next.js 4 before 4.2.3 has Directory Traversal under the /_next request namespace.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
| GitHub Advisory | 1.0.0 to < 4.2.3 · Fixed in 4.2.3 | affected |
Nuclei templates
1ProjectDiscoveryHIGHZeit Next.js < 4.2.3 - Local File InclusionCVSS 7.5
Zeit Next.js before 4.2.3 is susceptible to local file inclusion under the /_next request namespace. An attacker can obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site.
Impact
An attacker can exploit this vulnerability to read sensitive files, execute arbitrary code, or launch further attacks.
Remediation
Upgrade to the latest version of Zeit Next.js (>=4.2.3) to mitigate this vulnerability.
WeaknessesCWE-22
AuthorsDhiyaneshDK
Template tagscve2018cvenextjslfitraversalzeitvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:zeit:next.js:4.0.0:*:*:*:*:*:*:*
Shodan: html:"/_next/static"
Shodan: http.html:"/_next/static"
Shodan: cpe:"cpe:2.3:a:zeit:next.js"
FOFA: body="/_next/static"
https://github.com/PortSwigger/j2ee-scan/blob/master/src/main/java/burp/j2ee/issues/impl/NextFrameworkPathTraversal.java https://github.com/zeit/next.js/releases/tag/4.2.3 https://nvd.nist.gov/vuln/detail/CVE-2018-6184 https://github.com/lnick2023/nicenice https://github.com/masasron/vulnerability-research
Source: ProjectDiscovery
References
5github.com
https://github.com/vercel/next.js/releases/tag/4.2.3 github.com
https://github.com/zeit/next.js github.comConfirmation
https://github.com/zeit/next.js/releases/tag/4.2.3 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-6184