Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fix relative path traversal in twill:staticdocs:serve #2469

Merged
merged 1 commit into from
Feb 14, 2024

Conversation

ouuan
Copy link
Contributor

@ouuan ouuan commented Feb 10, 2024

Description

This fixes the relative path traversal vulnerability in the twill:staticdocs:serve command, which allows remote attackers to access any file on the host filesystem.

However, in reality, no one uses this command to host the docs while exposing it to the Internet.

Related Issues

Rejected as a security vulnerability in https://github.com/area17/twill/security/advisories/GHSA-9wwx-w6vv-q72c

this is not a vulnerability in the area17/twill software published on Packagist, as the command you are referring to is made for project maintainers in a local environnement, to contribute to the docs.

@CLAassistant
Copy link

CLAassistant commented Feb 10, 2024

CLA assistant check
All committers have signed the CLA.

@ifox ifox merged commit 81f5a14 into area17:3.x Feb 14, 2024
11 checks passed
@ouuan ouuan deleted the staticdocs-serve-path-traversal branch February 14, 2024 09:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

3 participants