MEDIUM
GHSA-7p7c-pvvx-2vx3
hyper-staticfile's improper validation of Windows paths could lead to directory traversal attack
Details
Path resolution in `hyper-staticfile` didn't correctly validate Windows paths, meaning paths like `/foo/bar/c:/windows/web/screen/img101.png` would be allowed and respond with the contents of `c:/windows/web/screen/img101.png`. Thus users could potentially read files anywhere on the filesystem.
This only impacts Windows. Linux and other unix likes are not impacted by this.
Are you affected?
Enter the version of the package you're using.
Affected packages
crates.io/hyper-staticfile
Introduced in:
0Fixed in: 0.9.2Upgrade hyper-staticfile to 0.9.2 or newer (ecosystem crates.io).
crates.io/hyper-staticfile
Introduced in:
0.10.0-alpha.1Fixed in: 0.10.0-alpha.2Upgrade hyper-staticfile to 0.10.0-alpha.2 or newer (ecosystem crates.io).
References
- https://github.com/stephank/hyper-staticfile/issues/35[WEB]
- https://github.com/stephank/hyper-staticfile/pull/36[WEB]
- https://github.com/stephank/hyper-staticfile/commit/1e40e31d64bc6b32e595d24074092dcf84410b2b[WEB]
- https://github.com/stephank/hyper-staticfile[PACKAGE]
- https://rustsec.org/advisories/RUSTSEC-2022-0069.html[WEB]