Commit 536cc642 authored by Tim Graham's avatar Tim Graham
Browse files

[1.6.x] Prevented arbitrary file inclusion with {% ssi %} tag and relative paths.

Thanks Rainer Koirikivi for the report and draft patch.

This is a security fix; disclosure to follow shortly.

Backport of 7fe5b656 from master
parent ef3604a0
Loading
Loading
Loading
Loading
+2 −0
Original line number Diff line number Diff line
"""Default tags used by the template system, available to all templates."""
from __future__ import unicode_literals

import os
import sys
import re
from datetime import datetime
@@ -332,6 +333,7 @@ class RegroupNode(Node):
        return ''

def include_is_allowed(filepath):
    filepath = os.path.abspath(filepath)
    for root in settings.ALLOWED_INCLUDE_ROOTS:
        if filepath.startswith(root):
            return True
+31 −0
Original line number Diff line number Diff line
@@ -1832,3 +1832,34 @@ class RequestContextTests(unittest.TestCase):
            template.Template('{% include "child" only %}').render(ctx),
            'none'
        )


class SSITests(TestCase):
    def setUp(self):
        self.this_dir = os.path.dirname(os.path.abspath(upath(__file__)))
        self.ssi_dir = os.path.join(self.this_dir, "templates", "first")

    def render_ssi(self, path):
        # the path must exist for the test to be reliable
        self.assertTrue(os.path.exists(path))
        return template.Template('{%% ssi "%s" %%}' % path).render(Context())

    def test_allowed_paths(self):
        acceptable_path = os.path.join(self.ssi_dir, "..", "first", "test.html")
        with override_settings(ALLOWED_INCLUDE_ROOTS=(self.ssi_dir,)):
            self.assertEqual(self.render_ssi(acceptable_path), 'First template\n')

    def test_relative_include_exploit(self):
        """
        May not bypass ALLOWED_INCLUDE_ROOTS with relative paths

        e.g. if ALLOWED_INCLUDE_ROOTS = ("/var/www",), it should not be
        possible to do {% ssi "/var/www/../../etc/passwd" %}
        """
        disallowed_paths = [
            os.path.join(self.ssi_dir, "..", "ssi_include.html"),
            os.path.join(self.ssi_dir, "..", "second", "test.html"),
        ]
        with override_settings(ALLOWED_INCLUDE_ROOTS=(self.ssi_dir,)):
            for path in disallowed_paths:
                self.assertEqual(self.render_ssi(path), '')