VDB
Sign up
CRITICAL9.8

GHSA-54xj-q58h-9x57

Arbitrary File Write in iobroker.admin

Quick fix

GHSA-54xj-q58h-9x57 — iobroker.admin: upgrade to the fixed version with the command below.

npm install iobroker.admin@3.6.12

Details

Versions of `iobroker.admin` prior to 3.6.12 are vulnerable to Path Traversal. The package fails to restrict access to folders outside of the intended folder in the `/log/` route, which may allow attackers to include arbitrary files in the system. An attacker would need to be authenticated to perform the attack but the package has authentication disabled by default.

## Recommendation

Upgrade to version 3.6.12 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/iobroker.admin
Introduced in: 0Fixed in: 3.6.12
Fixnpm install iobroker.admin@3.6.12

References