Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Template files accessible #1964

Closed
vtcdanh opened this issue Nov 14, 2022 · 0 comments
Closed

Template files accessible #1964

vtcdanh opened this issue Nov 14, 2022 · 0 comments
Assignees
Labels
bug Something isn't working security
Milestone

Comments

@vtcdanh
Copy link

vtcdanh commented Nov 14, 2022

Expose information

Description

When I run the fusionauth server using the docker image and I access the following urls: /bin /lib /web /template /3rd-party-licenses...
The above urls cause the fusionauth server to go to another page
Especially when I access the path /template/fusionauth.properties or /bin/start.sh it will download that file, and it will reveal the password of the database. And path /lib show libary folder that potentially lets attacker know if we used a vulnerable library

Affects versions

1.40.0

Steps to reproduce

Steps to reproduce the behavior:

  1. Start FusionAuth server with docker image
  2. Go to http://localhost:9011/template/fusionauth.properties or http://localhost:9011/bin/start.sh
  3. See error

Expected behavior

it will download a file fusionauth.properties.

Screenshots

image

Platform

(Please complete the following information)

  • Device: Desktop
  • OS: Window, Linux
  • Browser + version : Chrome, Version 107.0.5304.88 (Official Build) (64-bit)
  • Database: PostgresSQL version 12.9

Community guidelines

All issues filed in this repository must abide by the FusionAuth community guidelines.

Additional context

@vtcdanh vtcdanh changed the title Expose information Expose internal directories Nov 14, 2022
@robotdan robotdan added the bug Something isn't working label Nov 14, 2022
@robotdan robotdan self-assigned this Nov 14, 2022
@robotdan robotdan added this to Backlog in FusionAuth Issues via automation Nov 14, 2022
@robotdan robotdan added this to the 1.41.1 milestone Nov 14, 2022
@robotdan robotdan moved this from Backlog to In progress in FusionAuth Issues Nov 14, 2022
@robotdan robotdan moved this from In progress to Code complete in FusionAuth Issues Nov 14, 2022
@robotdan robotdan changed the title Expose internal directories Template files accessible Nov 15, 2022
FusionAuth Issues automation moved this from Code complete to Done Nov 17, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working security
Projects
FusionAuth Issues
  
Delivered
Development

No branches or pull requests

2 participants