Skip to content

Harden file uploads against path traversal. - #3420

Open
rjbartson wants to merge 1 commit into
apache:masterfrom
rjbartson:fix/filetraversal
Open

rjbartson wants to merge 1 commit into
apache:masterfrom
rjbartson:fix/filetraversal

Conversation

@rjbartson

Copy link
Copy Markdown

Description

Hardens file writes in FileSvc against path traversal and applies the check consistently across every caller.

  • save_file now validates the filename on every call, not just multipart uploads.
    Sink mode (target_dir + basename) runs the full _validate_filename check (character whitelist, ../separator/NUL rejection, base64-looking names).
    Path mode ('' + relative path) validates each path component structurally, then both modes enforce realpath containment under the parent directory.

  • Agent contact handlers (DNS, FTP, Gist, Slack) validate the agent-supplied filename before saving and log/drop the upload on failure, instead of relying on save_file alone.

  • create_exfil_sub_directory and create_exfil_operation_directory now reject dir_name values that resolve outside exfil_dir (e.g. ../ or absolute paths from X-Request-ID or agent paw). create_exfil_operation_directory also raises instead of indexing an empty list when no operation matches the agent.

  • Report and event log writers no longer route through create_exfil_sub_directory, since they write under reports_dir, not exfil_dir; they create their directory directly.

Type of change

  • Bug fix (security hardening, non-breaking)

How Has This Been Tested?

  • Built and ran the server in Docker; confirmed agent uploads, ability/source persistence, and operation report/event log writing still work.
  • Ran pytest tests/services/test_file_svc.py tests/security/test_filename_validation.py, including new tests:
    • test_create_exfil_sub_directory_rejects_escape (relative ../ and absolute dir_name)
    • test_create_exfil_operation_directory_rejects_escape
    • existing test_save_file_rejects_path_traversal updated for the new validation error

Checklist

  • My code follows the style guidelines of this project
  • I have performed a self-review of my own code
  • I have made corresponding changes to the documentation
  • I have added tests that prove my fix is effective or that my feature works
caldera_test

Validate names on every save_file path and keep exfil directory creation contained under exfil_dir.

Co-authored-by: Cursor <cursoragent@cursor.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant