github.com
https://github.com/Foddy/node-red-contrib-huemagic CVE-2021-25864
HIGHNuclei
Path Traversal in node-red-contrib-huemagic
Record summary
CVE-2021-25864 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
node-red-contrib-huemagic 3.0.0 is affected by hue/assets/..%2F Directory Traversal.in the res.sendFile API, used in file hue-magic.js, to fetch an arbitrary file.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Dec 24, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
huemagicBrowse dgtl / huemagic | VulnCheck | Version data not supplied | |
node-red-contrib-huemagicBrowse npm / node-red-contrib-huemagic | GitHub Advisory | Through 3.0.0 | affected |
Nuclei templates
1ProjectDiscoveryHIGHHue Magic 3.0.0 - Local File InclusionCVSS 7.5
Hue Magic 3.0.0 is susceptible to local file inclusion via the res.sendFile API.
Impact
The LFI vulnerability can lead to unauthorized access to sensitive files, potentially exposing sensitive information or allowing for further exploitation.
Remediation
Apply the latest security patch or update to a non-vulnerable version of Hue Magic.
WeaknessesCWE-22
Authors0x_Akoko
Template tagscve2021cvehuemagiclfidgtlnode.jsvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:dgtl:huemagic:3.0.0:*:*:*:*:node.js:*:*
Shodan: title:"NODE-RED"
Shodan: http.title:"node-red"
FOFA: title="node-red"
Google: intitle:"node-red"
https://github.com/Foddy/node-red-contrib-huemagic/issues/217 https://nvd.nist.gov/vuln/detail/CVE-2021-25864 https://github.com/ARPSyndicate/cvemon https://github.com/ARPSyndicate/kenzer-templates
Source: ProjectDiscovery
References
3github.com
https://github.com/Foddy/node-red-contrib-huemagic/issues/217 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-25864