PT-2023-12101 · Unknown · Node-Red-Contrib-Huemagic
Martinzhou2015
·
Published
2023-08-11
·
Updated
2023-08-16
·
CVE-2021-26504
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
node-red-contrib-huemagic version 3.0.0
Description
The issue allows remote attackers to gain sensitive information via a crafted request in the
res.sendFile API in hue-magic.js. This is a Directory Traversal vulnerability, which can be exploited by sending a specifically designed request to the affected system.Recommendations
For node-red-contrib-huemagic version 3.0.0, consider disabling the
res.sendFile function in hue-magic.js until a patch is available to prevent potential exploitation. Restrict access to sensitive information and files to minimize the risk of unauthorized access.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Node-Red-Contrib-Huemagic