VDB
Sign up
HIGH

GHSA-qmfx-75ff-8mw6

Listing of upload directory contents possible

Quick fix

GHSA-qmfx-75ff-8mw6 — github.com/ThomasLeister/prosody-filer: upgrade to the fixed version with the command below.

go get github.com/ThomasLeister/prosody-filer@v1.0.1

Details

There's an security issue in prosody-filer versions **< 1.0.1** which leads to unwanted directory listings of download directories.

An attacker is able to list previous uploads of a certain user by shortening the URL and accessing a URL subdirectors other than `/upload/` (or the corresponding user defined root dir)

Version 1.0.1 and later fix this problem and allow only direct file access if the full path is known. Directory listings are blocked entirely.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/ThomasLeister/prosody-filer
Introduced in: 0Fixed in: 1.0.1
Fixgo get github.com/ThomasLeister/prosody-filer@v1.0.1

References