User avatar
daniel:// stenberg:// @bagder@mastodon.social
1y
We got this "HIGH security problem" reported for earlier today:

"The -o / --output parameter in cURL does not restrict or sanitize file paths. When passed relative traversal sequences (e.g., ../../), cURL writes files outside the current working directory, allowing arbitrary file overwrite. In automated or privileged environments (CI/CD, root containers), this leads to Remote Code Execution (RCE), privilege escalation, and supply chain risk."

Never a dull moment.
⭐3😆1:neocat_googly_woozy@pl.eragon.re:1
27
10
0
5
User avatar
🪨 @Varpie@peculiar.florist
1y
@bagder I think it's serious enough to warrant a full new category of security issues, called Local Code Execution (LCE)
⭐4
0
0
0
4