Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8v4j-7jgf-5rg9

Опубликовано: 31 янв. 2023
Источник: github
Github: Прошло ревью

Описание

Warp vulnerable to Path Traversal via Improper validation of Windows paths

Path resolution in warp::filters::fs::dir didn't correctly validate Windows paths meaning paths like /foo/bar/c:/windows/web/screen/img101.png would be allowed and respond with the contents of c:/windows/web/screen/img101.png. Thus users could potentially read files anywhere on the filesystem.

This only impacts Windows. Linux and other unix likes are not impacted by this.

Пакеты

Наименование

warp

rust
Затронутые версииВерсия исправления

< 0.3.3

0.3.3

Дефекты

CWE-22

Дефекты

CWE-22