CVE-2020-26299
JavaScript vulnerability analysis and mitigation

Overview

CVE-2020-26299 affects ftp-srv, an open-source FTP server designed to be simple yet configurable, in versions before 4.4.0. The vulnerability allows clients of FTP servers utilizing ftp-srv hosted on Windows machines to escape the FTP user's defined root folder using standard FTP commands like CWD and UPDR (GitHub Advisory).

Technical details

The vulnerability occurs when Windows separators exist within the path (''), where path.resolve leaves the upper pointers intact and allows the user to move beyond the root folder defined for that user. This path traversal vulnerability enables authenticated users to access directories outside their designated root folder (NVD). The issue has a CVSS v3.1 base score of 9.6 CRITICAL according to NVD, while GitHub rates it as MEDIUM with a score of 6.3 (NVD).

Impact

The vulnerability allows authenticated users to access files and directories outside their intended root directory on Windows systems. This could lead to unauthorized access to sensitive files and potential information disclosure on the hosting system (GitHub Advisory).

Exploitability

The vulnerability can be exploited by authenticated users using standard FTP commands. The attack requires low complexity and can be executed remotely with only low privileges required (NVD).

Mitigation and workarounds

The issue was patched in version 4.4.0 with commit 457b859450a37cba10ff3c431eb4aa67771122e3. For users unable to upgrade, the only workaround is to host the FTP server on a non-Windows operating system (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related JavaScript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2021-43309HIGH7.5
  • JavaScript logoJavaScript
  • uri-template-lite
NoYesAug 24, 2022
CVE-2022-24375HIGH7.5
  • JavaScript logoJavaScript
  • node-opcua
NoYesAug 24, 2022
CVE-2022-25231HIGH7.5
  • JavaScript logoJavaScript
  • node-opcua
NoYesAug 23, 2022
CVE-2022-21208HIGH7.5
  • JavaScript logoJavaScript
  • node-opcua
NoYesAug 23, 2022
CVE-2022-2932MEDIUM6.1
  • JavaScript logoJavaScript
  • mobiledoc-kit
NoYesAug 22, 2022

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management