{"id":"GHSA-qmfx-75ff-8mw6","summary":"Listing of upload directory contents possible","details":"There's an security issue in prosody-filer versions **\u003c 1.0.1** which leads to unwanted directory listings of download directories. \n\nAn attacker is able to list previous uploads of a certain user by shortening the URL and accessing a URL subdirectors other than `/upload/` (or the corresponding user defined root dir)\n\nVersion 1.0.1 and later fix this problem and allow only direct file access if the full path is known. Directory listings are blocked entirely.","aliases":["GO-2022-0407"],"modified":"2024-08-21T15:27:05.528441Z","published":"2021-05-27T18:41:00Z","database_specific":{"github_reviewed_at":"2021-05-24T21:22:08Z","nvd_published_at":null,"cwe_ids":[],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/ThomasLeister/prosody-filer/security/advisories/GHSA-qmfx-75ff-8mw6"}],"affected":[{"package":{"name":"github.com/ThomasLeister/prosody-filer","ecosystem":"Go","purl":"pkg:golang/github.com/ThomasLeister/prosody-filer"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.0.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/05/GHSA-qmfx-75ff-8mw6/GHSA-qmfx-75ff-8mw6.json"}}],"schema_version":"1.9.0"}