{"id":"GHSA-qmfx-75ff-8mw6","aliases":["GO-2022-0407"],"url":"https://o3.security/vulnerability/GHSA-qmfx-75ff-8mw6","summary":"Listing of upload directory contents possible","details":"There's an security issue in prosody-filer versions **< 1.0.1** which leads to unwanted directory listings of download directories. \n\nAn attacker is able to list previous uploads of a certain user by shortening the URL and accessing a URL subdirectors other than `/upload/` (or the corresponding user defined root dir)\n\nVersion 1.0.1 and later fix this problem and allow only direct file access if the full path is known. Directory listings are blocked entirely.","published":"2021-05-27T18:41:00Z","modified":"2024-08-21T15:27:05.528441Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/ThomasLeister/prosody-filer","fixedVersion":"1.0.1"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/ThomasLeister/prosody-filer/security/advisories/GHSA-qmfx-75ff-8mw6"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-08-21T15:27:05.528441Z"}}