HIGH7.5
GHSA-cmch-296j-wfvw
Arbitrary File Write in iobroker.js-controller
Quick fix
GHSA-cmch-296j-wfvw — iobroker.js-controller: upgrade to the fixed version with the command below.
npm install iobroker.js-controller@2.0.25Details
Versions of `iobroker.controller` prior to 2.0.25 are vulnerable to Path Traversal. The package fails to restrict access to folders outside of the intended `/adapter/<adapter-name>` folder, which may allow attackers to include arbitrary files in the system. An attacker would need to be authenticated to perform the attack but the package has authentication disabled by default.
## Recommendation
Upgrade to version 2.0.25 or later.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/iobroker.js-controller
Introduced in:
0Fixed in: 2.0.25Fix
npm install iobroker.js-controller@2.0.25