VDB
Sign up
MEDIUM

GHSA-7p7c-pvvx-2vx3

hyper-staticfile's improper validation of Windows paths could lead to directory traversal attack

Details

Path resolution in `hyper-staticfile` didn't correctly validate Windows paths, meaning paths like `/foo/bar/c:/windows/web/screen/img101.png` would be allowed and respond with the contents of `c:/windows/web/screen/img101.png`. Thus users could potentially read files anywhere on the filesystem.

This only impacts Windows. Linux and other unix likes are not impacted by this.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/hyper-staticfile
Introduced in: 0Fixed in: 0.9.2

Upgrade hyper-staticfile to 0.9.2 or newer (ecosystem crates.io).

crates.io/hyper-staticfile
Introduced in: 0.10.0-alpha.1Fixed in: 0.10.0-alpha.2

Upgrade hyper-staticfile to 0.10.0-alpha.2 or newer (ecosystem crates.io).

References