fix: prevent tar symlink traversal in archive extraction

Archives passed to git:from-archive and certs:add were extracted without symlink or path validation, allowing a crafted archive to write arbitrary files anywhere writable by the dokku user via symlink traversal. Extraction now pre-scans entries for absolute paths, parent traversal, and unsafe symlinks, applies the GNU tar `--no-unsafe-links` flag when available, and validates symlinks after extraction.
This commit is contained in:
Jose Diaz-Gonzalez
2026-05-09 12:54:42 -04:00
parent 2974830e8f
commit 2df0791fcd
7 changed files with 394 additions and 4 deletions

View File

@@ -41,6 +41,9 @@ dokku certs:add node-js-app < cert-key.tar
cat yourdomain_com.crt yourdomain_com.ca-bundle > server.crt
```
> [!NOTE]
> Archives passed to `certs:add` are validated before extraction to prevent path traversal and symlink escape attacks. Archives containing absolute paths, parent directory traversal entries, or symlinks pointing outside the extraction directory will be rejected.
#### SSL and Multiple Domains
When an SSL certificate is associated to an application, the certificate will be associated with _all_ domains currently associated with said application. Your certificate _should_ be associated with all of those domains, otherwise accessing the application will result in SSL errors. If you wish to remove one of the domains from the application, refer to the [domain configuration documentation](/docs/configuration/domains.md).

View File

@@ -32,3 +32,12 @@ Finally, if the archive url is specified as `--`, the archive will be fetched fr
```shell
curl -sSL https://github.com/dokku/smoke-test-app/releases/download/2.0.0/smoke-test-app.tar | dokku git:from-archive node-js-app --
```
## Archive Safety
Archive contents are validated before extraction to prevent path traversal and symlink escape attacks. Archives containing absolute paths, parent directory traversal entries (`..`), or symlinks pointing outside the extraction directory are rejected.
The following limits can be configured via environment variables:
- `DOKKU_ARCHIVE_MAX_SIZE` - maximum archive size in bytes (default: `1073741824`, 1 GiB)
- `DOKKU_ARCHIVE_MAX_FILES` - maximum number of entries in an archive (default: `10000`)