Vulnerabilities/

Arbitrary File Write in iobroker.js-controller

Severity:
High

Description

Versions of iobroker.controller prior to 2.0.25 are vulnerable to Path Traversal. The package fails to restrict access to folders outside of the intended /adapter/<adapter-name> folder, which may allow attackers to include arbitrary files in the system.

Recommendation

Update the iobroker.js-controller package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
iobroker.js-controller
Anything's wrong? Let us know Last updated on January 09, 2023

This issue is available in SmartScanner Professional

See Pricing