VDB
Sign up
MEDIUM

GHSA-wwh2-r387-g5rm

tower-http's improper validation of Windows paths could lead to directory traversal attack

Details

`tower_http::services::fs::ServeDir` didn't correctly validate Windows paths meaning paths like `/foo/bar/c:/windows/web/screen/img101.png` would be allowed and respond with the contents of `c:/windows/web/screen/img101.png`. Thus users could potentially read files anywhere on the filesystem. This only impacts Windows. Linux and other unix likes are not impacted by this.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/tower-http
Introduced in: 0.2.0Fixed in: 0.2.1

Upgrade tower-http to 0.2.1 or newer (ecosystem crates.io).

crates.io/tower-http
Introduced in: 0Fixed in: 0.1.3

Upgrade tower-http to 0.1.3 or newer (ecosystem crates.io).

References