VDB
Sign up
HIGH7.5

GHSA-cmch-296j-wfvw

Arbitrary File Write in iobroker.js-controller

Quick fix

GHSA-cmch-296j-wfvw — iobroker.js-controller: upgrade to the fixed version with the command below.

npm install iobroker.js-controller@2.0.25

Details

Versions of `iobroker.controller` prior to 2.0.25 are vulnerable to Path Traversal. The package fails to restrict access to folders outside of the intended `/adapter/<adapter-name>` folder, which may allow attackers to include arbitrary files in the system. An attacker would need to be authenticated to perform the attack but the package has authentication disabled by default.

## Recommendation

Upgrade to version 2.0.25 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/iobroker.js-controller
Introduced in: 0Fixed in: 2.0.25
Fixnpm install iobroker.js-controller@2.0.25

References