Uploaded image for project: 'Service Packs and Hot Fixes'
  1. Service Packs and Hot Fixes
  2. MNT-12301

It is possible to download any readable file from the server

    Details

    • Type: Service Pack Request
    • Status: Closed
    • Resolution: Fixed
    • Affects Version/s: 4.2.N
    • Fix Version/s: 4.2.4
    • Component/s: Alfresco Explorer
    • Labels:
    • Environment:
      Ubuntu + 4.2.3 OOTB

      Description

      It is possible to download files from the server hosting Alfresco, that are not even in the repository.

      [steps to reproduce]
      1 - Set up a new 4.2.3 environment on Ubuntu using the installer and default values for the installation folder
      2 - Browse to http://server:port/alfresco/dr?contentUrl=store://../../../../../../../../../../../../etc/passwd
      3 - Login as admin

      [observed behaviour]
      The requested /etc/passwd server file is being downloaded to the client.
      It could be any file.

      [expected behaviour]
      Only the files needed by Alfresco should be accessible. All others should not.

        Attachments

          Structure

            Activity

              People

              • Assignee:
                closedbugs Closed Bugs (Inactive)
                Reporter:
                jbruinaud Julien Bruinaud [X] (Inactive)
              • Votes:
                0 Vote for this issue
                Watchers:
                23 Start watching this issue

                Dates

                • Created:
                  Updated:
                  Resolved:

                  Time Tracking

                  Estimated:
                  Original Estimate - Not Specified
                  Not Specified
                  Remaining:
                  Remaining Estimate - 0 minutes
                  0m
                  Logged:
                  Time Spent - 4 hours
                  4h

                    Structure Helper Panel