-
Notifications
You must be signed in to change notification settings - Fork 86
New issue
Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? # to your account
Directory traversal attack allowed when running in debug mode #159
Labels
Comments
Thanks for the report. I'll open a PR ASAP. |
Fix is released in v6.3.0. Thanks for finding the vulnerability @5225225. |
I'll file a https://rustsec.org/ vuln today to hopefully get anyone on vulnerable versions to upgrade, assuming they run cargo-audit or similar. |
Also, the readme / changelog needs to be updated. |
Ahh I forgot to push my commit. Thanks. |
This was referenced Nov 30, 2021
# for free
to join this conversation on GitHub.
Already have an account?
# to comment
This code will (assuming you have the correct number of
../
s), print out the contents of your/etc/passwd
.The text was updated successfully, but these errors were encountered: