- Reported
-
- Issued
-
- Package
-
apimock-server
(crates.io)
- Type
-
Vulnerability
- Categories
-
- Keywords
-
#path-traversal
#http
#file-serving
- Aliases
-
- References
-
- CVSS Score
- 8.2
HIGH
- CVSS Details
-
- Attack Complexity
- Low
- Attack Requirements
- Present
- Attack Vector
- Network
- Privileges Required
- None
- Availability Impact to the Subsequent System
- None
- Confidentiality Impact to the Subsequent System
- None
- Integrity Impact to the Subsequent System
- None
- User Interaction
- None
- Availability Impact to the Vulnerable System
- None
- Confidentiality Impact to the Vulnerable System
- High
- Integrity Impact to the Vulnerable System
- None
- CVSS Vector
- CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
- Patched
-
Description
The file-serving fallback joined a request-derived path onto the
configured response directory and checked only that the result existed,
never that it stayed inside that directory. A request containing a raw
.. segment could read any file readable by the process, returned with
HTTP 200.
Read-only: no write, no code execution.
Exposure depends on the bind address. The default is 127.0.0.1;
deployments binding 0.0.0.0 or a LAN address are reachable from the
network. Most HTTP clients normalise .. away before sending, so
reaching it requires a client that does not.
All published versions before 5.19.1 are affected. Fixed in 5.19.1 by
canonicalising each resolved path and rejecting anything outside its
base directory.
This advisory also covers apimock 5.x, which depends on
apimock-server. apimock 4.x predates the crate split and carries its
own advisory for the same issue, fixed in 4.8.1.
Advisory available under CC0-1.0
license.