Opened 6 years ago

Closed 21 months ago

#27659 closed Bug (fixed)

Arbritrary file overrides in startproject/app template extraction

Reported by: Florian Apolloner Owned by: nobody
Component: Utilities Version: dev
Severity: Normal Keywords:
Cc: Florian Apolloner Triage Stage: Accepted
Has patch: no Needs documentation: no
Needs tests: no Patch needs improvement: no
Easy pickings: no UI/UX: no

Description

Note: This was reported as security issue intially by me, but we think that this is more hardening than an actual issue -- if you are downloading untrusted archives the content can be much worse anyways…

The issue here is that tar files (and probably zip files too), can store full and/or relative paths and therefore escape out of the extraction root.

Attached is an initial WIP to show the issue and possible solution.

Attachments (1)

patch.diff (3.1 KB) - added by Florian Apolloner 6 years ago.

Download all attachments as: .zip

Change History (4)

Changed 6 years ago by Florian Apolloner

Attachment: patch.diff added

comment:1 Changed 6 years ago by Anton Samarchyan

Has patch: set

comment:2 Changed 6 years ago by Florian Apolloner

Needs tests: set
Patch needs improvement: set

comment:3 Changed 21 months ago by Mariusz Felisiak

Has patch: unset
Needs tests: unset
Patch needs improvement: unset
Resolution: fixed
Status: newclosed
Note: See TracTickets for help on using tickets.
Back to Top