Lack of data validation - Path Traversal In apimock
Description
Path traversal in apimock's file-serving fallback
The file-serving fallback joined a request-derived path onto the
configured response directory and checked only that the result existed,
never that it stayed inside that directory. A request containing a raw
.. segment could read any file readable by the process, returned with
HTTP 200.
Read-only: no write, no code execution.
On the 4.x line apimock is a single crate containing the serving code.
Fixed in 4.8.1 by canonicalising each resolved path and rejecting
anything outside its base directory.
apimock 5.0.0 and later are not affected by this advisory. From
5.0.0 the serving code moved to the apimock-server crate, which
apimock depends on; that crate carries its own advisory for the same
issue, fixed in 5.19.1.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
cargo | 4.8.1 | ||
cargo | 5.19.1 |
Aliases
References