Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

GitHub Security Lab (GHSL) Vulnerability Report, Alist #5477

Closed
4 tasks done
Kwstubbs opened this issue Nov 5, 2023 · 4 comments
Closed
4 tasks done

GitHub Security Lab (GHSL) Vulnerability Report, Alist #5477

Kwstubbs opened this issue Nov 5, 2023 · 4 comments
Labels
bug Something isn't working

Comments

@Kwstubbs
Copy link

Kwstubbs commented Nov 5, 2023

Please make sure of the following things

  • I have read the documentation.
    我已经阅读了文档

  • I'm sure there are no duplicate issues or discussions.
    我确定没有重复的issue或讨论。

  • I'm sure it's due to AList and not something else(such as Network ,Dependencies or Operational).
    我确定是AList的问题,而不是其他原因(例如网络依赖操作)。

  • I'm sure this issue is not fixed in the latest version.
    我确定这个问题在最新版本中没有被修复。

AList Version / AList 版本

v3.28.0

Driver used / 使用的存储驱动

local

Describe the bug / 问题描述

Github Security Lab has submitted a vulnerability report at https://github.com/alist-org/alist/security/advisories/GHSA-6cg9-7cgv-727q. Please let us know if any the maintainers of Alist are able to see this report by replying in the advisory. We look forward to helping you fix this issue. Thank you.

Reproduction / 复现链接

Can be found in vulnerability report.

Config / 配置

Default

Logs / 日志

No response

@Kwstubbs Kwstubbs added the bug Something isn't working label Nov 5, 2023
Copy link

welcome bot commented Nov 5, 2023

Thanks for opening your first issue here! Be sure to follow the issue template!

Copy link

github-actions bot commented Nov 5, 2023

@itsHenry35
Copy link
Contributor

sorry that I misunderstood you, i think you should email or tag him if it's urgent

@Kwstubbs
Copy link
Author

Kwstubbs commented Nov 6, 2023

@xhofe has responded in the draft advisory

@xhofe xhofe closed this as completed Nov 11, 2023
# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
bug Something isn't working
Projects
None yet
Development

No branches or pull requests

3 participants