From 7a9c0e31eca4958f5fba053cfea9e64a2ea58509 Mon Sep 17 00:00:00 2001 From: Marcus Efraimsson Date: Tue, 19 May 2020 17:16:15 +0200 Subject: [PATCH] Only allow 32 hexadecimal digits for the avatar hash --- pkg/api/avatar/avatar.go | 16 +++++++++++----- 1 file changed, 11 insertions(+), 5 deletions(-) diff --git a/pkg/api/avatar/avatar.go b/pkg/api/avatar/avatar.go index d2d33df144b..6768f9807cc 100644 --- a/pkg/api/avatar/avatar.go +++ b/pkg/api/avatar/avatar.go @@ -15,14 +15,14 @@ import ( "net/http" "net/url" "path/filepath" + "regexp" "strconv" - "strings" "sync" "time" "github.com/grafana/grafana/pkg/infra/log" + "github.com/grafana/grafana/pkg/models" "github.com/grafana/grafana/pkg/setting" - "gopkg.in/macaron.v1" gocache "github.com/patrickmn/go-cache" ) @@ -73,9 +73,15 @@ type CacheServer struct { cache *gocache.Cache } -func (this *CacheServer) Handler(ctx *macaron.Context) { - urlPath := ctx.Req.URL.Path - hash := urlPath[strings.LastIndex(urlPath, "/")+1:] +var validMD5 = regexp.MustCompile("^[a-fA-F0-9]{32}$") + +func (this *CacheServer) Handler(ctx *models.ReqContext) { + hash := ctx.Params("hash") + + if len(hash) != 32 || !validMD5.MatchString(hash) { + ctx.JsonApiErr(404, "Avatar not found", nil) + return + } var avatar *Avatar obj, exists := this.cache.Get(hash)