diff options
| author | Bryce Kwon <bryce@brycekwon.com> | |
|---|---|---|
| committer | Bryce Kwon <bryce@brycekwon.com> | |
| commit | ||
| parent | ||
| tree | ||
| download | ||
Reject option-like revisions in the log walk
The log page passed the `id` query parameter to git's revision parser
without resolving it and ahead of the end-of-options marker. A value
like `id=--output=/path` was then parsed as an option, so an
unauthenticated request could create or truncate any file the server
user could write. No valid ref or object name begins with a dash.
| -rw-r--r-- | source/ui-log.c | 12 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
1 file changed, 12 insertions, 0 deletions
diff --git a/source/ui-log.c b/source/ui-log.c index d3610d3..0a3fc0a 100644 --- a/source/ui-log.c +++ b/source/ui-log.c @@ -381,6 +381,18 @@ void cgit_print_log(const char *tip, int ofs, int cnt, char *grep, char *pattern if (!tip) tip = ctx.qry.head; tip = disambiguate_ref(tip, &must_free_tip); + if (tip && tip[0] == '-') { + /* setup_revisions() parses a leading-dash argument as an + * option, so a tip like the id= value "--output=<path>" would + * be handled by git as a request to write an arbitrary file. + * No valid ref or object name begins with a dash, so refuse it. + */ + cgit_print_error_page(400, "Bad request", "Invalid revision"); + if (must_free_tip) + free((char *)tip); + strvec_clear(&rev_argv); + return; + } strvec_push(&rev_argv, tip); if (grep && pattern && *pattern) { |
