Skip to content

directory traversal in gitblit v1.9.2 #1409

@xxcdd

Description

@xxcdd

When i request GET /resources//../WEB-INF/web.xml using burp suite, i get the raw content of web.xml
GET /resources//../ can get all files in Directory: /resources/

This can cause security issue, hope to fix it.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions