Bug 2172792 (CVE-2023-25579)
| Summary: | CVE-2023-25579 nextcloud: potential directory traversal in OC\Files\Node\Folder::getFullPath | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | Dhananjay Arunesh <darunesh> | 
| Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> | 
| Status: | CLOSED UPSTREAM | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | Keywords: | Security | 
| Target Milestone: | --- | ||
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | If docs needed, set a value | |
| Doc Text: | the 'OC\Files\Node\Folder::getFullPath()' function was validating and normalizing the string in the wrong order. The function is used in the 'newFile()' and 'newFolder()' items, which may allow to creation of paths outside of ones own space and overwriting data from other users with crafted paths. | Story Points: | --- | 
| Clone Of: | Environment: | ||
| Last Closed: | 2023-02-23 11:35:28 UTC | Type: | --- | 
| Regression: | --- | Mount Type: | --- | 
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2172793, 2172794 | ||
| Bug Blocks: | |||
| 
        
          Description
        
        
          Dhananjay Arunesh
        
        
        
        
        
          2023-02-23 06:09:38 UTC
        
       Created nextcloud tracking bugs for this issue: Affects: epel-all [bug 2172794] Affects: fedora-all [bug 2172793] This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products. |