Security issue in uacme.sh
pmconrad opened this issue · comments
Peter Conrad commented
Line 39 in 5afdaf0
The externally controlled TOKEN
variable (by the ACME server) is used to construct a path into which an externally controlled value $AUTH
is written. This can be exploited by the ACME server to overwrite arbitrary files with arbitrary content.
Peter Conrad commented
That was fast, thanks!