Next.js Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) Vulnerability - CVE-2017-16877 - Vulnerability Database
Next.js Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) Vulnerability - CVE-2017-16877
High
Reference:
CVE-2017-16877
Title:
Next.js Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) Vulnerability
Overview:
ZEIT Next.js before 2.4.1 has directory traversal under the /_next and /static request namespace allowing attackers to obtain sensitive information.