CVE-2023-40274
Summary
| CVE | CVE-2023-40274 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-08-14 01:15:00 UTC |
| Updated | 2023-08-22 17:47:00 UTC |
| Description | An issue was discovered in zola 0.13.0 through 0.17.2. The custom implementation of a web server, available via the "zola serve" command, allows directory traversal. The handle_request function, used by the server to process HTTP requests, does not account for sequences of special path control characters (../) in the URL when serving a file, which allows one to escape the webroot of the server and read arbitrary files from the filesystem. |
Risk And Classification
Problem Types: CWE-22
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| LFI in zola serve · Issue #2257 · getzola/zola · GitHub | MISC | github.com | |
| Fix LFI in `zola serve` by adeadfed · Pull Request #2258 · getzola/zola · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 996210 Rust (Rust) Security Update for zola (GHSA-xvv9-5j67-3rpq)