Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qrqq-9c63-xfrg

Опубликовано: 11 авг. 2022
Источник: github
Github: Прошло ревью

Описание

tower-http's improper validation of Windows paths could lead to directory traversal attack

tower_http::services::fs::ServeDir didn't correctly validate Windows paths, meaning paths like /foo/bar/c:/windows/web/screen/img101.png would be allowed and respond with the contents of c:/windows/web/screen/img101.png. Thus users could potentially read files anywhere on the filesystem.

This only impacts Windows. Linux and other unix likes are not impacted by this.

See tower-http#204 for more details.

Пакеты

Наименование

tower-http

rust
Затронутые версииВерсия исправления

= 0.2.0

0.2.1

Наименование

tower-http

rust
Затронутые версииВерсия исправления

< 0.1.3

0.1.3