mirror of
https://github.com/ZoneMinder/zoneminder.git
synced 2026-10-02 23:45:08 -04:00
fix: stop image proxy following redirects past the SSRF guard refs GHSA-v2qc-p8cq-g4pc
The proxy= handler in web/views/image.php validates the resolved address of the URL host against FILTER_FLAG_NO_RES_RANGE, then fetches with fopen() using PHP's default follow_location=1. A host that passes the check could answer 302 to 127.0.0.1 (or ::1, 169.254.169.254) and the stream wrapper would request it, returning the loopback content. Set follow_location to 0 in the http stream context so a 3xx is not followed. The same $opts is reused for the digest auth retry, so both fetches are covered. Camera discovery has no need for redirects. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> (cherry picked from commit ec71edad630ff614eaae499146d33fd780449715)
This commit is contained in:
1 parent
911362d873
commit
21f88bfcee
1 file changed
+4
-1
+4
-1
@@ -117,7 +117,10 @@ if (!empty($_REQUEST['proxy'])) {
|
||||
'http'=>array(
|
||||
'method'=>$method,
|
||||
#'header'=>"Accept-language: en\r\n" .
|
||||
'ignore_errors' => true
|
||||
'ignore_errors' => true,
|
||||
// The SSRF guard above only validated $host. Following a redirect would
|
||||
// connect to a Location the guard never checked (e.g. 127.0.0.1).
|
||||
'follow_location' => 0,
|
||||
#"Cookie: foo=bar\r\n"
|
||||
),
|
||||
'ssl'=>array(
|
||||
|
||||
Reference in new issue
Block a user