Bugzilla – Bug 1214237
VUL-0: CVE-2023-40274: zola: directory traversal when using the "serve" subcommand
Last modified: 2023-08-16 14:01:20 UTC
CVE-2023-40274 An issue was discovered in zola 0.13.0 through 0.17.2. The custom implementation of a web server, available via the "zola serve" command, allows directory traversal. The handle_request function, used by the server to process HTTP requests, does not account for sequences of special path control characters (../) in the URL when serving a file, which allows one to escape the webroot of the server and read arbitrary files from the filesystem. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-40274 https://www.cve.org/CVERecord?id=CVE-2023-40274 https://github.com/getzola/zola/issues/2257 https://github.com/getzola/zola/pull/2258
This is an autogenerated message for OBS integration: This bug (1214237) was mentioned in https://build.opensuse.org/request/show/1103952 Factory / zola
Not sure if the PR really did fix things. I just applied it as a patch. Feel free to change it to RESOLVED [FIXED] once confirmed :D