Overview
In OpenAtlas, the size parameter influenced the directory path used by a file endpoint. A low-privileged user could escape the intended directory and access files outside the uploads area.
Technical findings
At /display/<filename>, the size parameter selected a subdirectory. The value was not restricted to valid sizes or directory names and was incorporated directly into the constructed filesystem path.
An authenticated user could therefore redirect the target path outside the intended directory. Technically, this constitutes a path traversal / local file inclusion issue.
Configuration files make this especially serious: database credentials, Flask secrets or similar keys can enable subsequent attacks far beyond the initial file read.
Why it matters
Exploitation requires a valid low-privileged session. What matters next is which files the application process can read. Configuration files and secrets can quickly turn file disclosure into a much larger compromise.
Potential impact
- Authenticated users with minimal privileges may read files outside the intended directory, including configuration files and secrets.
Remediation
- Upgrade to OpenAtlas 8.13.0 or later.
- Validate the size parameter against a strict allowlist of expected values.
- Canonicalize resolved file paths and ensure the result remains inside the intended base directory.
- Avoid storing secrets unnecessarily within application paths and apply least-privilege filesystem permissions.
Affected and fixed versions
Disclosure timeline
- Discovery
Identified during an on-premises penetration test.
- Report submitted
Sent technical details and reproduction steps to the vendor.
- Fix confirmed
OpenAtlas confirmed that the finding had been addressed.
- CVE assignment
Received the CVE ID during coordinated disclosure.