VDB
KO
LOW 3.1

GHSA-grm4-wm43-9jh5

Contao: Possible path traversal in job download URIs

Quick fix

GHSA-grm4-wm43-9jh5 — contao/contao: upgrade to the fixed version with the command below.

composer require contao/contao:^5.7.7

Details

## Summary

An authenticated backend user who can access one job can request an attachment identifier containing `../` segments and make the job attachment download endpoint read a file from another job directory inside `var/job-attachments`.

The controller authorizes only the `jobUuid` route parameter. The later attachment lookup joins that authorized job UUID with the attacker-controlled `identifier`, then passes the combined path to the virtual filesystem. `VirtualFilesystem::resolve()` canonicalizes the whole path and only rejects paths that escape the filesystem mount, so `authorized-job/../victim-job/debug_log.csv` becomes `victim-job/debug_log.csv`.

This is a cross-job authorization bypass for known job attachment paths. It is not a practical brute-force against unknown jobs because job directories are UUID v4 values.

## Root Cause

`JobsController::downloadJobAttachment()` checks access to the route `jobUuid` before loading the attachment:

```php $job = $this->jobs->getByUuid($jobUuid);

if (!$job || !$this->jobs->hasAccess($job)) { throw $this->createNotFoundException(); }

$attachment = $this->jobs->getAttachment($jobUuid, $identifier); ```

`Jobs::getAttachment()` then resolves a path built from the authorized job UUID and the attacker-controlled identifier:

```php $fileItem = $this->jobAttachmentsStorage->get($this->getAttachmentIdentifier($job, $identifier)); ```

```php return $job->getUuid().'/'.$identifier; ```

`VirtualFilesystem::resolve()` canonicalizes the combined path. It rejects absolute paths and paths that start with `..`, but it does not preserve the authorized job directory as a boundary:

```php $path = Path::canonicalize($location);

if (str_starts_with($path, '..')) { throw new \OutOfBoundsException(...); }

return Path::join($this->prefix, $path); ```

Therefore:

```text <authorized-job>/../<victim-job>/debug_log.csv ```

canonicalizes to:

```text <victim-job>/debug_log.csv ```

which remains inside the `job-attachments` filesystem mount and is accepted.

## Recommended Fix

Treat the attachment identifier as a filename, not a path:

- Reject `/`, `\`, NUL, and dot-segment components in `identifier`. - Add a route requirement that prevents slashes in `{identifier}` if nested attachment paths are not intended. - After resolving, assert the canonical relative path starts with `<authorized-job-uuid>/` before returning a `FilesystemItem`. - Apply the same identifier validation in `Jobs::addAttachment()` so future producers/extensions cannot write outside the owning job directory.

### Impact A low-privileged backend user can read another job's attachment if they know or obtain the target job UUID and attachment filename. Built-in crawler jobs attach CSV logs such as `debug_log.csv`, `broken-link-checker_log.csv`, and `search-index_log.csv`, which can contain crawled URLs, referring URLs, tags, and error messages.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist / contao/contao
Introduced in: 5.7.0 Fixed in: 5.7.7
Fix composer require contao/contao:^5.7.7
Packagist / contao/core-bundle
Introduced in: 5.7.0 Fixed in: 5.7.7
Fix composer require contao/core-bundle:^5.7.7

References