MEDIUM
GHSA-wwh2-r387-g5rm
tower-http's improper validation of Windows paths could lead to directory traversal attack
Details
`tower_http::services::fs::ServeDir` didn't correctly validate Windows paths meaning paths like `/foo/bar/c:/windows/web/screen/img101.png` would be allowed and respond with the contents of `c:/windows/web/screen/img101.png`. Thus users could potentially read files anywhere on the filesystem. This only impacts Windows. Linux and other unix likes are not impacted by this.
Are you affected?
Enter the version of the package you're using.
Affected packages
crates.io/tower-http
Introduced in:
0.2.0Fixed in: 0.2.1Upgrade tower-http to 0.2.1 or newer (ecosystem crates.io).
crates.io/tower-http
Introduced in:
0Fixed in: 0.1.3Upgrade tower-http to 0.1.3 or newer (ecosystem crates.io).