Prevent URLs like file:/./ to circumvent permission check
Signed-off-by: Christian König <github@yubiuser.dev>
This commit is contained in:
+1
-1
@@ -726,7 +726,7 @@ gravity_DownloadBlocklistFromUrl() {
|
|||||||
# to match the effective runtime user of FTL; otherwise, check the current user's read access
|
# to match the effective runtime user of FTL; otherwise, check the current user's read access
|
||||||
# (e.g., in Docker or when invoked by a non-root user). The target must
|
# (e.g., in Docker or when invoked by a non-root user). The target must
|
||||||
# resolve to a regular file and be readable by the evaluated user.
|
# resolve to a regular file and be readable by the evaluated user.
|
||||||
if [[ "${url}" == "file://"* ]]; then
|
if [[ "${url}" == "file:/"* ]]; then
|
||||||
# Get the file path
|
# Get the file path
|
||||||
file_path=$(echo "${url}" | cut -d'/' -f3-)
|
file_path=$(echo "${url}" | cut -d'/' -f3-)
|
||||||
# Check if the file exists and is a regular file (i.e. not a socket, fifo, tty, block). Might still be a symlink.
|
# Check if the file exists and is a regular file (i.e. not a socket, fifo, tty, block). Might still be a symlink.
|
||||||
|
|||||||
Reference in New Issue
Block a user