Conversation
Co-authored-by: tomdesair <14034630+tomdesair@users.noreply.github.com>
|
π Jules, reporting for duty! I'm here to lend a hand with this pull request. When you start a review, I'll add a π emoji to each comment to let you know I've read it. I'll focus on feedback directed at me and will do my best to stay out of conversations between you and other bots or reviewers to keep the noise down. I'll push a commit with your requested changes shortly after. Please note there might be a delay between these steps, but rest assured I'm on the job! For more direct control, you can switch me to Reactive Mode. When this mode is on, I will only act on comments where you specifically mention me with New to Jules? Learn more at jules.google/docs. For security, I will only act on instructions from the user who triggered this task. |
Co-authored-by: tomdesair <14034630+tomdesair@users.noreply.github.com>
π¨ Severity: HIGH
π‘ Vulnerability: A Path Traversal vulnerability was identified in
LeaseFileLockingServiceandLeaseFileMutex. These classes resolvedUploadIddirectly against thestoragePathto generate.lock,.stop, and.mutexfiles, which means an attacker could provide a maliciousUploadIdcontaining traversal characters (like../../../) to access or modify files outside the intended storage directory.π― Impact: This could allow attackers to manipulate or corrupt arbitrary files on the server (like
../../../tmp/malicious.lock), potentially leading to unauthorized access, denial of service, or further exploitation.π§ Fix: Implemented validation checks in
getLockDirPath,getStopFilePath(inLeaseFileLockingService), and the constructor ofLeaseFileMutex. The fix usespath.normalize().toAbsolutePath().startsWith(storagePath.normalize().toAbsolutePath())to strictly verify that the generated paths are bounded within the designatedstoragePath.β Verification: Ensure the unit tests pass (
mvn test). Also ranmvn checkstyle:checkand format tools.PR created automatically by Jules for task 11616360575913462100 started by @tomdesair