7.5 HIGH
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): High (H)
- Privileges Required (PR): None (N)
- User Interaction (UI): Required (R)
- Scope (S): Unchanged (U)
- Confidentiality (C): High (H)
- Integrity (I): High (H)
- Availability (A): High (H)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): High (H)
- Modified Privileges Required (MPR): None (N)
- Modified User Interaction (MUI): Required (R)
- Modified Confidentiality (MC): High (H)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): High (H)
- Modified Availability (MA): High (H)
Activity log
- Created suggestion
Copier: Percent-encoded dot segments in template URLs can allow trusted-prefix escape (Incomplete fix for trust-prefix bypass)
Copier is a library and CLI app for rendering project templates. From 9.5.0 through 9.16.0, percent-encoded parent-directory segments or encoded path separators in a template URL can match a configured trusted repository prefix before an HTTP server or Git transport decodes the path, allowing unsafe template features from a repository outside the trusted prefix to run after user interaction. This issue is fixed in version 9.17.0.
References
-
https://github.com/copier-org/copier/security/advisories/GHSA-34mv-rjq9-5mch exploitx_refsource_CONFIRM
-
https://github.com/copier-org/copier/releases/tag/v9.17.0 x_refsource_MISC
Affected products
- ==>= 9.5.0, <= 9.16.0
Matching in nixpkgs
pkgs.copier
Library and command-line utility for rendering projects templates
pkgs.apksigcopier
Copy/extract/patch android apk signatures & compare APKs
pkgs.gnomeExtensions.copier
Copy text notes to clipboard via a panel indicator
pkgs.python313Packages.copier
Library and command-line utility for rendering projects templates
pkgs.python314Packages.copier
Library and command-line utility for rendering projects templates
pkgs.gnomeExtensions.notifications-copier
Automatically copies authentication tokens, PINs, and one-time codes from GNOME notifications to the clipboard. Reads notification content to detect verification codes and OTPs without storing or transmitting data.
-
nixos-unstable -
- nixos-unstable-small 3
pkgs.python313Packages.copier-template-tester
CLI and pre-commit tool for testing copier
pkgs.python314Packages.copier-template-tester
CLI and pre-commit tool for testing copier
Package maintainers
-
@obfusk FC Stegerman <flx@obfusk.net>
-
@savtrip Sav Tripodi
-
@honnip Jung seungwoo <me@honnip.page>
-
@yajo Jairo Llopis <yajo.sk8@gmail.com>
-
@aduh95 Antoine du Hamel <duhamelantoine1995@gmail.com>