S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2017-14849 Scanner

CVE-2017-14849 scanner - Directory Traversal vulnerability in Node.js

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.4k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
6
Vulnerabilities Found
confirmed findings
References
CVECVE-2017-14849
7.5
CVSS

Node.js 8.5.0 before 8.6.0 allows remote attackers to access unintended files, because a change to ".." handling was incompatible with the pathname validation used by unspecified community modules.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

Node.js is a popular open-source, cross-platform JavaScript runtime environment that runs on various operating systems. It is mostly used for building scalable network applications, such as web servers, real-time chat applications, and RESTful APIs. It is also favored by developers due to its excellent performance, lightweight design, and flexibility.

CVE-2017-14849 is a dangerous vulnerability that was discovered in Node.js 8.5.0 before 8.6.0. This vulnerability allows remote attackers to access unintended files or system resources that are not supposed to be exposed to the public. The problem was caused by a change in the handling of the ".." notation, which resulted in an incompatibility with the pathname validation used by some community modules. 

Exploiting CVE-2017-14849 could lead to dire consequences, such as the exposure of confidential data, the execution of malicious code, and the complete takeover of the system. Attackers could use this vulnerability to gain unauthorized access to databases, files, or any other resource that Node.js is responsible for managing. This could result in serious harm, especially for applications that deal with sensitive or personal data.

s4e.io offers a unique platform for individuals and organizations to gain valuable insights into the security of their digital assets. With pro features such as automated scanning, vulnerability reporting, and expert advice, this platform provides an all-in-one solution for those who want to ensure the safety and protection of their systems. By using this platform, users can easily and quickly learn about any vulnerabilities in their digital assets and take immediate action to fix them.

 

REFERENCES

Solution Advice

To protect against this vulnerability, the following precautions can be taken:

  • Update Node.js to version 8.6.0 or newer, which includes a fix for this vulnerability.
  • Use a reputable security tool to scan your system for signs of exploitation or suspicious activity.
  • Minimize the risk of exposure by configuring Node.js to only allow access to trusted sources and resources.
  • Limit privileges and permissions for Node.js processes to only what is strictly required for the application to function.
  • Regularly review the codebase of your Node.js applications for vulnerabilities and update dependencies to their latest version.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2017-14849 scanner - Directory Traversal vulnerability in Node.js | S4E