CVE-2018-3717
published 2018-06-07CVE-2018-3717: connect node module before 2.14.0 suffers from a Cross-Site Scripting (XSS) vulnerability due to a lack of validation of file in directory.js middleware.
PriorityP423medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EPSS
1.33%
68.0th percentile
connect node module before 2.14.0 suffers from a Cross-Site Scripting (XSS) vulnerability due to a lack of validation of file in directory.js middleware.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | connect | >= 0 < 2.14.0 | 2.14.0 |
| debian | node-connect | < node-connect 3.0.0-1 (bookworm) | node-connect 3.0.0-1 (bookworm) |
| hackerone | connect_node_module | — | — |
| node-connect | node-connect | >= 0 < 3.0.0-1 | 3.0.0-1 |
| node-connect | node-connect | >= 0 < 3.0.0-1 | 3.0.0-1 |
| node-connect | node-connect | >= 0 < 3.0.0-1 | 3.0.0-1 |
| node-connect | node-connect | >= 0 < 3.0.0-1 | 3.0.0-1 |
| sencha | connect | < 2.14.0 | 2.14.0 |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
osv5.4MEDIUM
vendor_debian5.4MEDIUM
vendor_redhat5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
nodejs-connect: XSS due to a lack of validation of file in directory.js middleware
vendor_redhat·2018-06-07·CVSS 5.4
CVE-2018-3717 [MEDIUM] CWE-79 nodejs-connect: XSS due to a lack of validation of file in directory.js middleware
nodejs-connect: XSS due to a lack of validation of file in directory.js middleware
connect node module before 2.14.0 suffers from a Cross-Site Scripting (XSS) vulnerability due to a lack of validation of file in directory.js middleware.
Package: nodejs-connect (Red Hat Mobile Application Platform 4) - Not affected
Debian
CVE-2018-3717: node-connect - connect node module before 2.14.0 suffers from a Cross-Site Scripting (XSS) vuln...
vendor_debian·2018·CVSS 5.4
CVE-2018-3717 [MEDIUM] CVE-2018-3717: node-connect - connect node module before 2.14.0 suffers from a Cross-Site Scripting (XSS) vuln...
connect node module before 2.14.0 suffers from a Cross-Site Scripting (XSS) vulnerability due to a lack of validation of file in directory.js middleware.
Scope: local
bookworm: resolved (fixed in 3.0.0-1)
bullseye: resolved (fixed in 3.0.0-1)
forky: resolved (fixed in 3.0.0-1)
sid: resolved (fixed in 3.0.0-1)
trixie: resolved (fixed in 3.0.0-1)
GHSA
Cross-Site Scripting in connect
ghsa·2018-07-26
CVE-2018-3717 [MEDIUM] CWE-79 Cross-Site Scripting in connect
Cross-Site Scripting in connect
connect node module before 2.14.0 suffers from a Cross-Site Scripting (XSS) vulnerability due to a lack of validation of file in directory.js middleware.
OSV
Cross-Site Scripting in connect
osv·2018-07-26
CVE-2018-3717 [MEDIUM] Cross-Site Scripting in connect
Cross-Site Scripting in connect
connect node module before 2.14.0 suffers from a Cross-Site Scripting (XSS) vulnerability due to a lack of validation of file in directory.js middleware.
OSV
CVE-2018-3717: connect node module before 2
osv·2018-06-07·CVSS 5.4
CVE-2018-3717 [MEDIUM] CVE-2018-3717: connect node module before 2
connect node module before 2.14.0 suffers from a Cross-Site Scripting (XSS) vulnerability due to a lack of validation of file in directory.js middleware.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-3717 nodejs-connect: XSS due to a lack of validation of file in directory.js middleware [fedora-all]
bugzilla·2018-06-07·CVSS 5.4
CVE-2018-3717 [MEDIUM] CVE-2018-3717 nodejs-connect: XSS due to a lack of validation of file in directory.js middleware [fedora-all]
CVE-2018-3717 nodejs-connect: XSS due to a lack of validation of file in directory.js middleware [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue aff
Bugzilla
CVE-2018-3717 nodejs-connect: XSS due to a lack of validation of file in directory.js middleware [epel-6]
bugzilla·2018-06-07·CVSS 5.4
CVE-2018-3717 [MEDIUM] CVE-2018-3717 nodejs-connect: XSS due to a lack of validation of file in directory.js middleware [epel-6]
CVE-2018-3717 nodejs-connect: XSS due to a lack of validation of file in directory.js middleware [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-6.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the followi
Bugzilla
CVE-2018-3717 nodejs-connect: XSS due to a lack of validation of file in directory.js middleware
bugzilla·2018-06-07·CVSS 5.4
CVE-2018-3717 [MEDIUM] CVE-2018-3717 nodejs-connect: XSS due to a lack of validation of file in directory.js middleware
CVE-2018-3717 nodejs-connect: XSS due to a lack of validation of file in directory.js middleware
connect node module before 2.14.0 suffers from a Cross-Site Scripting (XSS) vulnerability due to a lack of validation of file in directory.js middleware.
Upstream patch:
https://github.com/senchalabs/connect/commit/6d5dd30075d2bc4ee97afdbbe3d9d98d8d52d74b
References:
https://hackerone.com/reports/309394
https://hackerone.com/reports/309641
Discussion:
Created nodejs-connect tracking bugs for this issue:
Affects: epel-6 [bug 1588800]
Affects: fedora-all [bug 1588801]
https://github.com/senchalabs/connect/commit/6d5dd30075d2bc4ee97afdbbe3d9d98d8d52d74bhttps://hackerone.com/reports/309394https://hackerone.com/reports/309641https://github.com/senchalabs/connect/commit/6d5dd30075d2bc4ee97afdbbe3d9d98d8d52d74bhttps://hackerone.com/reports/309394https://hackerone.com/reports/309641
2018-06-07
Published