HIGH7.5
GHSA-xvv9-5j67-3rpq
zola Path Traversal vulnerability
Details
An issue was discovered in zola 0.13.0 through 0.17.2. The custom implementation of a web server, available via the "zola serve" command, allows directory traversal. The `handle_request` function, used by the server to process HTTP requests, does not account for sequences of special path control characters (`../`) in the URL when serving a file, which allows one to escape the webroot of the server and read arbitrary files from the filesystem.
Are you affected?
Enter the version of the package you're using.
Affected packages
crates.io/zola
Introduced in:
0.13.0No fixed version published yet for zola. Pin to a known-safe version or switch to an alternative.