REDHAT-BUG-2460233: Path Traversal
Let's Encrypt client and ACME library written in Go (Lego). Prior to 4.34.0, the webroot HTTP-01 challenge provider in lego is vulnerable to arbitrary file write and deletion via path traversal. A malicious ACME server can supply a crafted challenge token containing ../ sequences, causing lego to write attacker-influenced content to any path writable by the lego process. This vulnerability is fixed in 4.34.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
legoto a version that resolves this vulnerability.Fixed in 4.34.0
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2460233?
The severity of REDHAT-BUG-2460233 is high, rated at 7.
What vulnerability does REDHAT-BUG-2460233 describe?
REDHAT-BUG-2460233 describes a path traversal vulnerability in the webroot HTTP-01 challenge provider of the Lego ACME client.
How can REDHAT-BUG-2460233 be exploited?
REDHAT-BUG-2460233 can be exploited by a malicious ACME server supplying a crafted challenge token containing '../' sequences, leading to arbitrary file write and deletion.
What versions of Lego are affected by REDHAT-BUG-2460233?
REDHAT-BUG-2460233 affects versions of Go Lego prior to 4.34.0.
How do I fix REDHAT-BUG-2460233?
To fix REDHAT-BUG-2460233, upgrade to version 4.34.0 or later of the Lego ACME client.