rama has Stored XSS in ServeDir HTML directory listing via unescaped file names and URI path
Resolved: https://github.com/plabayo/rama/commit/89ddff578fd78bbebec99482d7030f28c07757a3
plabayo/rama contains a stored/reflected cross-site scripting issue in the ServeDir HTML directory listing feature.
When ServeDir is configured with DirectoryServeMode::HtmlFileList, file names and URI path components are inserted directly into generated HTML without HTML escaping. If an attacker can create or influence a file or directory name inside a served directory, they may inject HTML or JavaScript into the directory listing page.
This can execute script in the browser of any user who visits the affected directory listing.
plabayo/rama
rama-http/src/service/fs/serve_dir/open_file.rs
The HTML directory listing is constructed using string formatting and inserts untrusted values directly into HTML.
The directory listing row includes the file or directory name in both the link text and the href attribute:
rows.push(format!(
"<tr><td>{5} <a href=\"{1}{2}{0}\">{0}</a></td><td>{3}</td><td>{4}</td></tr>",
entry.name,
uri.path().trim_end_matches('/'),
...
));
The navigation breadcrumb also inserts URI path parts into generated HTML:
nav_parts.push(format!("<a href=\"{current_path}\">{part}</a>"));
The page title and heading also include the current URI path:
<title>Directory listing for .{0}</title>
<h1>Directory listing for .{0}</h1>
These values are not HTML-escaped before being embedded into the generated page.
If an application uses ServeDir with DirectoryServeMode::HtmlFileList, an attacker who can create or influence file names inside the served directory can inject HTML or JavaScript into the generated directory listing.
Possible impact includes:
The attack requires the directory listing feature to be enabled and the attacker to control or influence at least one file or directory name in the served path.
This proof of concept uses a benign payload.
Create a directory with a file name containing HTML:
mkdir rama-xss-test
cd rama-xss-test
touch '"><img src=x onerror=alert(document.domain)>.txt'
Serve this directory with Rama using ServeDir and DirectoryServeMode::HtmlFileList.
Example intended configuration:
ServeDir::new("rama-xss-test")
.with_directory_serve_mode(DirectoryServeMode::HtmlFileList)
Then visit the directory listing in a browser.
Expected behavior:
The file name should be displayed as text. Special characters such as <, >, ", and ' should be HTML-escaped.
Actual behavior:
The file name is inserted directly into the generated HTML. The browser interprets the injected HTML and executes the benign JavaScript payload.
All file names, directory names, URI path parts, and other untrusted values should be escaped before being inserted into HTML.
For example:
< should become <> should become >" should become "' should become '& should become &Untrusted values used inside HTML attributes should be escaped using an attribute-safe escaping function.
The directory listing is generated with format!() and inserts file names and path values directly into HTML without escaping.
Escape all untrusted values before inserting them into the generated HTML.
Recommended changes:
entry.name before using it as link text.href.Example test payloads:
"><img src=x onerror=alert(1)>.txt
<script>alert(1)</script>.txt
a&b.txt
quote"test.txt
single'test.txt
The secure output should render these as text only and should not create executable HTML or JavaScript.
Medium.
Suggested CVSS:
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Rationale:
ServeDir directory listings.This report is limited to the HTML directory listing generated by ServeDir when DirectoryServeMode::HtmlFileList is enabled.
This report is not claiming remote code execution on the server. The issue is browser-side cross-site scripting caused by unescaped file names and path values in generated HTML.
왜 이 VPI인가 (설명가능 · 실험적)
VPI 산정 기준
| 영향도 | 37.00 |
| 악용 신호(추가 악용신호 없음) | ×1.00 |
| VPI | 37.00 |
VPI 공식 vpi-v1 기준