Project

General

Profile

Actions

Bug #23606

closed

Creating files with the file explorer fails when using invalid character

Added by Nicolas CHARLES about 1 year ago. Updated 11 months ago.

Status:
Released
Priority:
N/A
Category:
Web - Config management
Target version:
Severity:
UX impact:
User visibility:
Effort required:
Priority:
0
Name check:
To do
Fix check:
Checked
Regression:
No

Description

I tried to create a file named

<script>alert("true");</script>
with the file explorer in directive page, saved it, and nothing seemed to have happened
Webapp log say
2023-10-18 18:59:37+0000 ERROR com.normation.rudder.rest.internal.SharedFilesAPI - An error occurred while looking into directory <- An error occurred. Cause was: NoSuchFileException: /var/rudder/configuration-repository/shared-files/<script>alert("true");</script>


Files

clipboard-202310191655-mgnm5.png (15 KB) clipboard-202310191655-mgnm5.png Alexis Mousset, 2023-10-19 16:55
Actions

Also available in: Atom PDF