GHSA-p6ph-3jx2-3337: OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search
An authorization bypass and information disclosure vulnerability exists in the search API of Openlist. Due to a non-separator-aware path check and unfiltered backend counting, a low-privileged user can bypass their assigned BasePath restrictions to discover and access metadata of files residing in unauthorized sibling directories.
References
- github.com/OpenListTeam/OpenList/commit/59bd3431408578f420895457554700cc9a52375a
- github.com/OpenListTeam/OpenList/commit/84ecda35aae2bd0020474086e6ddfd3aa2340679
- github.com/OpenListTeam/OpenList/releases/tag/v4.2.4
- github.com/OpenListTeam/OpenList/security/advisories/GHSA-p6ph-3jx2-3337
- github.com/advisories/GHSA-p6ph-3jx2-3337
Code Behaviors & Features
Detect and mitigate GHSA-p6ph-3jx2-3337 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →