QID 996210
Date Published: 2023-12-13
QID 996210: Rust (Rust) Security Update for zola (GHSA-xvv9-5j67-3rpq)
An issue was discovered in zola 0.13.0 through 0.17.2. The custom implementation of a web server, available via the "zola serve" command, allows directory traversal. The handle_request function, used by the server to process HTTP requests, does not account for sequences of special path control characters (../) in the URL when serving a file, which allows one to escape the webroot of the server and read arbitrary files from the filesystem.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-xvv9-5j67-3rpq for updates and patch information.
Vendor References
- GHSA-xvv9-5j67-3rpq -
github.com/advisories/GHSA-xvv9-5j67-3rpq
CVEs related to QID 996210
Software Advisories
| Advisory ID | Software | Component | Link |
|---|