google / gtm-session-fetcher

Google Toolbox for Mac - Session Fetcher
Apache License 2.0
247 stars 150 forks source link

Path Manipulation #212

Closed Shakihassan closed 4 years ago

Shakihassan commented 4 years ago

Attackers are able to control the file system path argument to removeItemAtURL:error:() at GTMSessionUploadFetcher.m line 1565, which allows them to access or modify otherwise protected files.Attackers are able to control the file system path argument which allows them to access or modify otherwise protected files.

Reported by fortify on demand

thomasvl commented 4 years ago

Dup of #171