HIGH
GHSA-qmfx-75ff-8mw6
Listing of upload directory contents possible
Quick fix
GHSA-qmfx-75ff-8mw6 — github.com/ThomasLeister/prosody-filer: upgrade to the fixed version with the command below.
go get github.com/ThomasLeister/prosody-filer@v1.0.1Details
There's an security issue in prosody-filer versions **< 1.0.1** which leads to unwanted directory listings of download directories.
An attacker is able to list previous uploads of a certain user by shortening the URL and accessing a URL subdirectors other than `/upload/` (or the corresponding user defined root dir)
Version 1.0.1 and later fix this problem and allow only direct file access if the full path is known. Directory listings are blocked entirely.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/ThomasLeister/prosody-filer
Introduced in:
0Fixed in: 1.0.1Fix
go get github.com/ThomasLeister/prosody-filer@v1.0.1