Uploaded image for project: 'Service Packs and Hot Fixes'
  1. Service Packs and Hot Fixes
  2. MNT-12301

It is possible to download any readable file from the server

    Details

      Description

      It is possible to download files from the server hosting Alfresco, that are not even in the repository.

      [steps to reproduce]
      1 - Set up a new 4.2.3 environment on Ubuntu using the installer and default values for the installation folder
      2 - Browse to http://server:port/alfresco/dr?contentUrl=store://../../../../../../../../../../../../etc/passwd
      3 - Login as admin

      [observed behaviour]
      The requested /etc/passwd server file is being downloaded to the client.
      It could be any file.

      [expected behaviour]
      Only the files needed by Alfresco should be accessible. All others should not.

        Attachments

          Structure

            Activity

              People

              • Assignee:
                closedbugs Closed Bugs
                Reporter:
                jbruinaud Julien Bruinaud [X] (Inactive)
              • Votes:
                0 Vote for this issue
                Watchers:
                23 Start watching this issue

                Dates

                • Created:
                  Updated:
                  Resolved:

                  Time Tracking

                  Estimated:
                  Original Estimate - Not Specified
                  Not Specified
                  Remaining:
                  Remaining Estimate - 0 minutes
                  0m
                  Logged:
                  Time Spent - 4 hours
                  4h

                    Structure Helper Panel