Page MenuHome GnuPG

Path traversal bug in gpg-wks-server
Closed, ResolvedPublic


Philipp Breuch reported problems with the gpg-wks-server. In particular a directory path traversal bug could be used to publish a key for a different address.

Event Timeline

werner created this task.
werner created this object in space Restricted Space.
werner created this object with edit policy "Contributor (Project)".
werner renamed this task from Pass traversal bug in gpg-wks-server to Path traversal bug in gpg-wks-server.Jul 27 2022, 8:20 AM
werner shifted this object from the Restricted Space space to the S1 Public space.Jul 27 2022, 11:43 AM
werner changed the task status from Open to Testing.Jul 27 2022, 12:33 PM

Fix will go into 2.2.37 and 2.3.8.

Note that migration to the new version will invalidate pending requests.

werner claimed this task.