Philipp Breuch reported problems with the gpg-wks-server. In particular a directory path traversal bug could be used to publish a key for a different address.
Description
Description
Revisions and Commits
Revisions and Commits
| rG GnuPG | |||
| rG73a98c139691 wkd: Bind the address to the nonce. | |||
| rG4c8792fa10b6 wkd: Bind the address to the nonce. | |||
Related Objects
Related Objects
Event Timeline
Comment Actions
Fix will go into 2.2.37 and 2.3.8.
Note that migration to the new version will invalidate pending requests.