← back
CVE-2017-16877

CVE-2017-16877

23Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 10%
exploitation probability
10%top 5% of all CVEs
observed exploitation
nono source reports it
ZEIT Next.js before 2.4.1 has directory traversal under the /_next and /static request namespace, allowing attackers to obtain sensitive information.
Affected products
n/a · n/a