-
Notifications
You must be signed in to change notification settings - Fork 66
Open
Description
The issue about local file inclusion at CesiumGS/gltf-pipeline#673 may also be relevant for the 3D Tiles Tools.
This applies to different levels:
- The 3D Tiles Tools are using
gltf-pipelineas a dependency. In some cases, the fix that is about to go intogltf-pipelinemight already resolve possible vulnerabilities in the 3D Tiles Tools - The 3D Tiles Tools are using
glTF-Transformas a depencency. The cases whereglTF-Transformmight allow such a Local File Inclusion have to be examined (I think that it does not have this vulnerability. In fact, I think that it hardly allows ~"external resources" at all, maybe exactly because of this. But this remains to be verified) - The 3D Tiles Tools tried to abstract away some resource handling the the
ResourceResolverand its implementation (FileResourceResolver). It simply rejectshttp(s)URIs, but there may be issues with other URIs (fileor/absoluteor../../../youAreNotSupposedToBeHereones)
Metadata
Metadata
Assignees
Labels
No labels