CVE-2017-16877
23Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 10%
exploitation probability
10%top 5% of all CVEs
observed exploitation
nono source reports it
ZEIT Next.js before 2.4.1 has directory traversal under the /_next and /static request namespace, allowing attackers to obtain sensitive information.
Affected products
n/a · n/a