Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fix (arbitrary) File Read #14

Open
qtc-de opened this issue Dec 13, 2023 · 0 comments
Open

Fix (arbitrary) File Read #14

qtc-de opened this issue Dec 13, 2023 · 0 comments

Comments

@qtc-de
Copy link

qtc-de commented Dec 13, 2023

Hi @ankushagarwal 👋,

private vulnerability reporting is unfortunately deactivated for this project, but the vulnerability was already disclosed in #1 anyway. In the current implementation, clients can simply provide absolute paths to escape from the intended webroot. However, I do not recommend merging #1 because:

  1. The fix suggested in this PR can be bypassed
  2. It adds a bypass for the allowed filetype list

Instead a different fix should be implemented.

I know, this repository is quite old and seems no longer to be maintained. However, the tool is quite popular and I saw it being used by a production system recently. Therefore, you should go ahead and reserve a CVE for this issue. If there is no reaction, after some time, I will go ahead an claim a CVE for this issue. Hope this is okay for you :)

Best regards
Tobias

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant