From 86d3b2ba811aa8168eb01a5a345d3b717889ab8a Mon Sep 17 00:00:00 2001 From: Adrian Lang Date: Thu, 1 Sep 2011 23:24:51 +0200 Subject: [PATCH] Fix directory traversal See https://ada.adrianlang.de/etherpad-lite-directory-traversal --- node/server.js | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/node/server.js b/node/server.js index 944e73703..3014423bd 100644 --- a/node/server.js +++ b/node/server.js @@ -99,7 +99,8 @@ async.waterfall([ app.get('/static/*', function(req, res) { res.header("Server", serverName); - var filePath = path.normalize(__dirname + "/.." + req.url.split("?")[0]); + var filePath = path.normalize(__dirname + "/.." + + req.url.replace(/\./g, '').split("?")[0]); res.sendfile(filePath, { maxAge: exports.maxAge }); });