VDB
Sign up
HIGH7.5

GHSA-xvv9-5j67-3rpq

zola Path Traversal vulnerability

Details

An issue was discovered in zola 0.13.0 through 0.17.2. The custom implementation of a web server, available via the "zola serve" command, allows directory traversal. The `handle_request` function, used by the server to process HTTP requests, does not account for sequences of special path control characters (`../`) in the URL when serving a file, which allows one to escape the webroot of the server and read arbitrary files from the filesystem.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/zola
Introduced in: 0.13.0

No fixed version published yet for zola. Pin to a known-safe version or switch to an alternative.

References