From 8941c3c6c15d0836b98bcbcdfd1c4d277edee580 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 3 Jan 2025 16:26:00 +0000 Subject: [PATCH] Publish GHSA-8fx8-pffw-w498 --- .../GHSA-8fx8-pffw-w498.json | 62 +++++++++++++++++++ 1 file changed, 62 insertions(+) create mode 100644 advisories/github-reviewed/2025/01/GHSA-8fx8-pffw-w498/GHSA-8fx8-pffw-w498.json diff --git a/advisories/github-reviewed/2025/01/GHSA-8fx8-pffw-w498/GHSA-8fx8-pffw-w498.json b/advisories/github-reviewed/2025/01/GHSA-8fx8-pffw-w498/GHSA-8fx8-pffw-w498.json new file mode 100644 index 00000000000..25ae79d8d53 --- /dev/null +++ b/advisories/github-reviewed/2025/01/GHSA-8fx8-pffw-w498/GHSA-8fx8-pffw-w498.json @@ -0,0 +1,62 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8fx8-pffw-w498", + "modified": "2025-01-03T16:24:34Z", + "published": "2025-01-03T16:24:34Z", + "aliases": [ + "CVE-2025-21609" + ], + "summary": "SiYuan has an arbitrary file deletion vulnerability", + "details": "### Summary\nA **arbitrary file deletion vulnerability** has been identified in the latest version of Siyuan Note. The vulnerability exists in the `POST /api/history/getDocHistoryContent` endpoint.An attacker can craft a payload to exploit this vulnerability, resulting in the deletion of arbitrary files on the server.\n\n### Details\nThe vulnerability can be reproduced by sending a crafted request to the `/api/history/getDocHistoryContent` endpoint.\n\nSending a request to the `/api/history/getDocHistoryContent` like:\n\n```\ncurl \"http://127.0.0.1:6806/api/history/getDocHistoryContent\" -X POST -H \"Content-Type: application/json\" -d '{\"historyPath\":\"\"}'\n```\n\nReplace `` with the absolute file path of the target file you wish to delete.\n\n\n\nThe `historyPath` parameter in the payload is processed by the `func getDocHistoryContent` in `api/history.go:133`.\n\nIn turn, `historyPath` is passed to the `func GetDocHistoryContent` located in `model/history.go:150` , which is the slink of the vulnerability.\n\nif `historyPath` exists and does not satisfy the `filesys.ParseJSONWithoutFix`, then it will be deleted by `os.RemoveAll`\n\n```go\nfunc GetDocHistoryContent(historyPath, keyword string, highlight bool) (id, rootID, content string, isLargeDoc bool, err error) {\n\tif !gulu.File.IsExist(historyPath) {\n\t\tlogging.LogWarnf(\"doc history [%s] not exist\", historyPath)\n\t\treturn\n\t}\n\n\tdata, err := filelock.ReadFile(historyPath)\n\tif err != nil {\n\t\tlogging.LogErrorf(\"read file [%s] failed: %s\", historyPath, err)\n\t\treturn\n\t}\n\tisLargeDoc = 1024*1024*1 <= len(data)\n\n\tluteEngine := NewLute()\n\thistoryTree, err := filesys.ParseJSONWithoutFix(data, luteEngine.ParseOptions)\n\tif err != nil {\n\t\tlogging.LogErrorf(\"parse tree from file [%s] failed, remove it\", historyPath)\n\t\tos.RemoveAll(historyPath)\n\t\treturn\n\t}\n\t...\n}\n```\n\n\n\n### PoC\n```\ncurl \"http://127.0.0.1:6806/api/history/getDocHistoryContent\" -X POST -H \"Content-Type: application/json\" -d '{\"historyPath\":\"\"}'\n```\n\n### Impact\narbitrary file deletion vulnerability\n", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Go", + "name": "github.com/siyuan-note/siyuan/kernel" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "database_specific": { + "last_known_affected_version_range": "< 0.0.0-20250103014808-d9887aeec1b2" + } + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/siyuan-note/siyuan/security/advisories/GHSA-8fx8-pffw-w498" + }, + { + "type": "WEB", + "url": "https://github.com/siyuan-note/siyuan/commit/d9887aeec1b27073bec66299a9a4181dc42969f3" + }, + { + "type": "PACKAGE", + "url": "https://github.com/siyuan-note/siyuan" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-459", + "CWE-552" + ], + "severity": "HIGH", + "github_reviewed": true, + "github_reviewed_at": "2025-01-03T16:24:34Z", + "nvd_published_at": null + } +} \ No newline at end of file