The receive root and destructive manifest operation are controlled by peer-supplied protocol/config data. Plain TCP has no authentication, TLS client authentication is optional, and manifest processing can invoke delete_extras without a server-side deletion policy. A client can therefore select an administrator-unintended destination or delete existing files beneath it.
Location
src/shared/config.c:312
src/server/server.c:41-52,90-103
src/shared/file.c:716-733
Validation
Send a valid configuration with an attacker-selected receive_root_directory, or send a manifest with count 0 followed by STATUS_FINISHED to a server with files under the selected root. Also test TLS with a configured CA but no client certificate.
Suggested implementation
Configure receive roots server-side, canonicalize and enforce an administrator-owned root, require authenticated/authorized peers for writes, gate deletion on server policy, and require SSL_VERIFY_FAIL_IF_NO_PEER_CERT when mutual TLS is configured. Add negative integration tests.
## Severity
Critical
## Description
The receive root and destructive manifest operation are controlled by peer-supplied protocol/config data. Plain TCP has no authentication, TLS client authentication is optional, and manifest processing can invoke delete_extras without a server-side deletion policy. A client can therefore select an administrator-unintended destination or delete existing files beneath it.
## Location
- src/shared/config.c:312
- src/server/server.c:41-52,90-103
- src/shared/file.c:716-733
## Validation
Send a valid configuration with an attacker-selected receive_root_directory, or send a manifest with count 0 followed by STATUS_FINISHED to a server with files under the selected root. Also test TLS with a configured CA but no client certificate.
## Suggested implementation
Configure receive roots server-side, canonicalize and enforce an administrator-owned root, require authenticated/authorized peers for writes, gate deletion on server policy, and require SSL_VERIFY_FAIL_IF_NO_PEER_CERT when mutual TLS is configured. Add negative integration tests.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Severity
Critical
Description
The receive root and destructive manifest operation are controlled by peer-supplied protocol/config data. Plain TCP has no authentication, TLS client authentication is optional, and manifest processing can invoke delete_extras without a server-side deletion policy. A client can therefore select an administrator-unintended destination or delete existing files beneath it.
Location
Validation
Send a valid configuration with an attacker-selected receive_root_directory, or send a manifest with count 0 followed by STATUS_FINISHED to a server with files under the selected root. Also test TLS with a configured CA but no client certificate.
Suggested implementation
Configure receive roots server-side, canonicalize and enforce an administrator-owned root, require authenticated/authorized peers for writes, gate deletion on server policy, and require SSL_VERIFY_FAIL_IF_NO_PEER_CERT when mutual TLS is configured. Add negative integration tests.