PT-2021-16821 · Node Red · Node-Red-Contrib-Huemagic

·

CVE-2021-25864

·

Published

2021-01-26

·

Updated

2023-08-16

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions node-red-contrib-huemagic version 3.0.0
Description The issue allows for Directory Traversal, enabling access to arbitrary files. This is achieved through the res.sendFile API in the file hue-magic.js, using the hue/assets/..%2F path.
Recommendations For node-red-contrib-huemagic version 3.0.0, consider disabling the res.sendFile API in the hue-magic.js file until a patch is available. Restrict access to the hue-magic.js file to minimize the risk of exploitation. Avoid using the hue/assets/..%2F path in the affected API endpoint until the issue is resolved.

Exploit

Fix

DoS

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-25864
GHSA-FRPW-JRWX-HCFV

Affected Products

Node-Red-Contrib-Huemagic