mirror of
https://github.com/NginxProxyManager/nginx-proxy-manager.git
synced 2026-04-25 09:25:55 +03:00
[PR #114] [MERGED] Fixed directory traversal vulnerability. #3190
Labels
No labels
awaiting feedback
bug
cannot reproduce
dns provider request
duplicate
enhancement
enhancement
enhancement
good first issue
help wanted
invalid
need more info
no certbot plugin available
product-support
pull-request
question
stale
troll
upstream issue
v2
v2
v2
v3
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
starred/nginx-proxy-manager-NginxProxyManager#3190
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
📋 Pull Request Information
Original PR: https://github.com/NginxProxyManager/nginx-proxy-manager/pull/114
Author: @jlesage
Created: 4/2/2019
Status: ✅ Merged
Merged: 4/2/2019
Merged by: @jc21
Base:
master← Head:fix-directory-traversal-vulnerability📝 Commits (1)
c6a4002Fixed directory traversal vulnerability.📊 Changes
1 file changed (+17 additions, -9 deletions)
View changed files
📝
src/backend/routes/main.js(+17 -9)📄 Description
Management interface can leak local file system. For example, accessing an url like this is allowed:
http://test.com:81/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fetc/passwd
This PR fixes this by not allowing access to resources outside
dist/.🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.