GHSA-qmfx-75ff-8mw6

    Dashboard / Vulnerabilities / GHSA-qmfx-75ff-8mw6

    GHSA-qmfx-75ff-8mw6

    Published: 27 May 2021Last Modified: 21 Aug 2024
    Aliases:

    Summary: Listing of upload directory contents possible

    Details: There's an security issue in prosody-filer versions **< 1.0.1** which leads to unwanted directory listings of download directories. An attacker is able to list previous uploads of a certain user by shortening the URL and accessing a URL subdirectors other than `/upload/` (or the corresponding user defined root dir) Version 1.0.1 and later fix this problem and allow only direct file access if the full path is known. Directory listings are blocked entirely.

    Affected packages

    Package

    Name: github.com/ThomasLeister/prosody-filer

    Purl: pkg:golang/github.com/ThomasLeister/prosody-filer

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -1.0.1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-qmfx-75ff-8mw6 | CVE-DB