Details
-
Bug
-
Resolution: Fixed
-
Blocker
-
2.5 M2
Description
Reproduction steps:
- Start office server on the wiki
- Insert a new comment with guest such as:
{{office reference="url:file:///etc/whois.conf"/}}
Expected result:
- the file should not be displayed, only PR user should be able (maybe?) to access a file from the host like this
Obtained result:
- the file is displayed to anyone once the comment is saved
Attachments
Issue Links
- causes
-
XWIKI-20324 SSRF - Retrieve sensitive data from server - Add Gadget
- Closed
- relates to
-
XWIKI-20449 Server side request forgery (SSRF) with the Office Viewer
- Closed