Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fixes CVE-2020-6563 #2243

Draft
wants to merge 1 commit into
base: master
Choose a base branch
from
Draft

Conversation

AlexV525
Copy link
Contributor

@AlexV525 AlexV525 commented Aug 1, 2024

downstream AstroxNetwork@f50270f

The request resolves CVE-2020-6563 which allows the file provider to access files in the sandbox by explicitly checking the file path and excluding potential results.

@AlexV525 AlexV525 marked this pull request as draft September 7, 2024 02:56
@pichillilorenzo
Copy link
Owner

Do you think that this is still necessary?

@AlexV525
Copy link
Contributor Author

Do you think that this is still necessary?

Yes it is, but it should somehow follow the defined provided path in the resource file. I haven't got time to investigate whether we can link them together.

@pichillilorenzo
Copy link
Owner

Do you have an example of an input and its expected output that your code should return? Something to test it with, thanks!

@AlexV525
Copy link
Contributor Author

Ah I used to have one, but it looks expired :(

@AlexV525
Copy link
Contributor Author

AlexV525 commented Sep 23, 2024

I think attachments in https://issues.chromium.org/issues/40052821#c_ts1596465909 should be able to reproduce the issue. Also https://bugzilla.mozilla.org/show_bug.cgi?id=1652360

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants