Skip to content

fix(webdav): contain temp-path resolution within the temp directory - #37939

Open
oidacra wants to merge 1 commit into
mainfrom
713-webdav-temp-path-hardening
Open

oidacra wants to merge 1 commit into
mainfrom
713-webdav-temp-path-hardening

Conversation

@oidacra

@oidacra oidacra commented Oct 7, 2026 •

Copy link
Copy Markdown
Member

Problem

WebDAV temp-path resolution joined request-derived input onto the temp directory
without containment, so a path with a parent-directory traversal could resolve
outside the intended temp root.

Fix

  • Add isWithinTempDir(File) to DotWebdavHelper: canonicalizes the candidate and
    the temp root, allowing only paths contained within the root (fail-closed).
  • Apply it in loadTempFile (returns null), createTempFile and createTempFolder
    (reject before creating), logging on rejection.
  • In-bounds operations, including dot-prefixed client temp files, are unaffected.

Tests

  • New integration test DotWebdavTempPathContainmentTest (registered in MainSuite3a):
    escaping paths rejected; in-bounds dot-prefixed temp file still resolves inside the
    root. Confirmed failing before the fix, passing after (Tests run: 3, Failures: 0).

Risk

Rollback-safe: no DB schema, ES mapping, API contract, or serialized-state change.

Fixes dotCMS/private-issues#713

@github-actions github-actions Bot added the Area : Backend PR changes Java/Maven backend code label Oct 7, 2026
@claude

claude Bot commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @oidacra's task in 2m 8s —— View job


I'll analyze this and get back to you.

WebDAV temp-storage paths and names come from the client. Resolve every temp
path strictly inside the temp directory (the directory itself is not a valid
resource), and require names that reach temp storage to be a single plain path
segment. Temp writes (copy, move, create file, create folder) build their target
through one helper and reject invalid input with 400 before touching the
filesystem. Rejections are logged without the request path.

Adds DotWebdavTempPathContainmentTest, registered in MainSuite3a.
@oidacra
oidacra force-pushed the 713-webdav-temp-path-hardening branch from f7ddc90 to 7a4bf22 Compare October 7, 2026 20:47

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Area : Backend PR changes Java/Maven backend code

Projects

Status: No status

Development

Successfully merging this pull request may close these issues.

1 participant