Exploiting webpack-dev-middleware Path Traversal (CVE-2024-29180)

Exploiting webpack-dev-middleware Path Traversal (CVE-2024-29180)

OS

2024.1.*
2020.3.*
2019.4.*

Screenshots from the blog posts

images/cly4f76ap0z9a1gmw761fg59r.pngimages/cly4f76ap0z9a1gmw761fg59r.png

Summary

In this post, we will analyze an automated exploit targeting vulnerable webpack-dev-middleware package. The specific vulnerability being targeted is a path traversal and the exploit pulls the user-supplied file from the target machine (provided that it exists).

general

Description

@secatgourity

190 posts

Total vcoins

123.8K

Social media links

Comments (0)