Impact
A flaw in the serveStatic method of restify node-restify versions up to 12.0.0 allows a remote attacker to craft a request path that includes traversal sequences and cause the server to serve files outside the intended static directory. This is a CWE-22 on the host file system, exposing sensitive data. The vulnerability description code; the impact is limited to information disclosure.
Affected Systems
All installations of restify node-restify 12.0.0 or earlier that use the serveStatic plugin in /lib/plugins/static.js. Any Node.js application that incorporates this static middleware is affected.
Risk and Exploitability
The CVSS score of 6.9 reflects moderate severity, while the EPSS score is < 1%, indicating a low but non-zero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, suggesting no documented widespread exploitation to date. However a standard HTTP request to the static endpoint, still deploys the vulnerable serveStatic method carries a remote information disclosure risk.
OpenCVE Enrichment