GHSA-x8wj-6m73-gfqp

Suggest an improvement
Source
https://github.com/advisories/GHSA-x8wj-6m73-gfqp
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/02/GHSA-x8wj-6m73-gfqp/GHSA-x8wj-6m73-gfqp.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-x8wj-6m73-gfqp
Aliases
Published
2020-02-18T18:59:24Z
Modified
2024-02-16T08:09:54.608578Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Relative Path Traversal (CWE-23) in chunked uploads in oneup/uploader-bundle
Details

Impact

The vulnerability was identified in the web service for a chunked file upload. While the names of the POST parameters vary with the used frontend, their values are always used in the same way to build a path where the chunks are stored and assembled temporarily. By not validating these parameters properly, OneupUploaderBundle is susceptible to a path traversal vulnerability which can be exploited to upload files to arbitrary folders on the filesystem. The assembly process can further be misused with some restrictions to delete and copy files to other locations.

The vulnerability can be exploited by any users that have legitimate access to the upload functionality and can lead to arbitrary code execution, denial of service and disclosure of confidential information.

Patches

Yes, see version 1.9.3 and 2.1.5.

References

https://owasp.org/www-community/attacks/Path_Traversal

Credits:

This security vulnerability was found by Thibaud Kehler of SySS GmbH. E-Mail: thibaud.kehler@syss.de

Database specific
{
    "nvd_published_at": "2020-02-05T14:15:00Z",
    "cwe_ids": [
        "CWE-22",
        "CWE-23"
    ],
    "severity": "HIGH",
    "github_reviewed": true,
    "github_reviewed_at": "2020-02-05T13:52:02Z"
}
References

Affected packages

Packagist / oneup/uploader-bundle

Package

Name
oneup/uploader-bundle
Purl
pkg:composer/oneup/uploader-bundle

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.0.0
Fixed
2.1.5

Affected versions

2.*

2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4

Packagist / oneup/uploader-bundle

Package

Name
oneup/uploader-bundle
Purl
pkg:composer/oneup/uploader-bundle

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.0.0
Fixed
1.9.3

Affected versions

v1.*

v1.0.0
v1.0.1
v1.1.0
v1.2.0
v1.2.1
v1.2.2
v1.3.0
v1.3.1

1.*

1.3.2
1.4.0
1.5.0
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
1.9.2