Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wwh2-r387-g5rm

Опубликовано: 17 июн. 2022
Источник: github
Github: Прошло ревью

Описание

tower-http's improper validation of Windows paths could lead to directory traversal attack

tower_http::services::fs::ServeDir didn't correctly validate Windows paths meaning paths like /foo/bar/c:/windows/web/screen/img101.png would be allowed and respond with the contents of c:/windows/web/screen/img101.png. Thus users could potentially read files anywhere on the filesystem. This only impacts Windows. Linux and other unix likes are not impacted by this.

Пакеты

Наименование

tower-http

rust
Затронутые версииВерсия исправления

>= 0.2.0, < 0.2.1

0.2.1

Наименование

tower-http

rust
Затронутые версииВерсия исправления

< 0.1.3

0.1.3

Дефекты

CWE-22

Дефекты

CWE-22