From 87d2750b39f6f2d54b7047225521a44dcd37e896 Mon Sep 17 00:00:00 2001 From: Tim Graham Date: Tue, 27 Aug 2013 21:06:33 -0400 Subject: [PATCH] [1.4.x] Prevented arbitrary file inclusion with {% ssi %} tag and relative paths. Thanks Rainer Koirikivi for the report and draft patch. This is a security fix; disclosure to follow shortly. Backport of 7fe5b656c9 from master --- django/template/defaulttags.py | 2 ++ tests/regressiontests/templates/tests.py | 31 ++++++++++++++++++++++++ 2 files changed, 33 insertions(+) diff --git a/django/template/defaulttags.py b/django/template/defaulttags.py index 954c5d6d19..f977901e93 100644 --- a/django/template/defaulttags.py +++ b/django/template/defaulttags.py @@ -1,5 +1,6 @@ """Default tags used by the template system, available to all templates.""" +import os import sys import re from datetime import datetime @@ -309,6 +310,7 @@ class RegroupNode(Node): return '' def include_is_allowed(filepath): + filepath = os.path.abspath(filepath) for root in settings.ALLOWED_INCLUDE_ROOTS: if filepath.startswith(root): return True diff --git a/tests/regressiontests/templates/tests.py b/tests/regressiontests/templates/tests.py index f74aa757e6..6b02c83cb8 100644 --- a/tests/regressiontests/templates/tests.py +++ b/tests/regressiontests/templates/tests.py @@ -1764,3 +1764,34 @@ class RequestContextTests(BaseTemplateResponseTest): template.Template('{% include "child" only %}').render(ctx), 'none' ) + + +class SSITests(unittest.TestCase): + def setUp(self): + self.this_dir = os.path.dirname(os.path.abspath(__file__)) + self.ssi_dir = os.path.join(self.this_dir, "templates", "first") + + def render_ssi(self, path): + # the path must exist for the test to be reliable + self.assertTrue(os.path.exists(path)) + return template.Template('{%% ssi %s %%}' % path).render(Context()) + + def test_allowed_paths(self): + acceptable_path = os.path.join(self.ssi_dir, "..", "first", "test.html") + with override_settings(ALLOWED_INCLUDE_ROOTS=(self.ssi_dir,)): + self.assertEqual(self.render_ssi(acceptable_path), 'First template\n') + + def test_relative_include_exploit(self): + """ + May not bypass ALLOWED_INCLUDE_ROOTS with relative paths + + e.g. if ALLOWED_INCLUDE_ROOTS = ("/var/www",), it should not be + possible to do {% ssi "/var/www/../../etc/passwd" %} + """ + disallowed_paths = [ + os.path.join(self.ssi_dir, "..", "ssi_include.html"), + os.path.join(self.ssi_dir, "..", "second", "test.html"), + ] + with override_settings(ALLOWED_INCLUDE_ROOTS=(self.ssi_dir,)): + for path in disallowed_paths: + self.assertEqual(self.render_ssi(path), '')