OSV 1.4.0 · github-reviewed · 修改于 2021-05-25 05:22
发布时间
2021-05-28 02:41
GitHub 审查时间
2021-05-25 05:22
NVD 发布时间
—
源文件
advisories/github-reviewed/2021/05/GHSA-qmfx-75ff-8mw6/GHSA-qmfx-75ff-8mw6.json
There's an security issue in prosody-filer versions < 1.0.1 which leads to unwanted directory listings of download directories.
An attacker is able to list previous uploads of a certain user by shortening the URL and accessing a URL subdirectors other than /upload/ (or the corresponding user defined root dir)
Version 1.0.1 and later fix this problem and allow only direct file access if the full path is known. Directory listings are blocked entirely.