Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal
Vulnerability Description
OpenList a file list program that supports multiple storage. Prior to 4.2.4, the authenticated /api/fs/batch_rename handler in server/handles/fsbatch.go authorizes only the source directory produced by user.JoinPath(req.SrcDir) and validates renameObject.NewName with checkRelativePath, but does not validate attacker-controlled renameObject.SrcName, supplied as src_name, before concatenating it with the authorized path and passing the result to fs.Rename. A user with rename permission can use traversal segments in src_name to make path normalization select a file outside the authorized directory and configured base path, resulting in cross-user file integrity loss, limited availability impact, and file-existence disclosure through success or error responses. This issue is fixed in version 4.2.4.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
OpenList Team OpenList 路径遍历漏洞
Vulnerability Description
OpenList Team OpenList是中国OpenList Team团队的一款清单管理工具。 OpenList Team OpenList 4.2.4之前版本存在路径遍历漏洞,该漏洞源于batch_rename处理器未验证src_name参数,可能导致路径遍历,造成跨用户文件完整性损失、有限可用性影响和文件存在性泄露。
CVSS Information
N/A
Vulnerability Type
N/A