Vulnerability GHSA-hgfg-j9pg-43xw
Summary
SiYuan discloses an administrator's open documents and search terms to anonymous readers
Details
Summary
/api/system/getConf serves Conf.UILayout to publish readers after passing it through FilterConfByPublishIgnore, whose only function is to filter that layout. The layout is written exclusively by setUILayout, which is administrator-gated, so what readers receive is the administrator's own live workspace state, re-saved on every tab open, close and focus change.
The filter that is supposed to protect it, filterLayoutItemByPublishIgnore, has four separate defects. Together they mean a single unauthenticated POST with no arguments returns the titles and identifiers of the administrator's open password-protected documents, the titles of documents in locked or closed notebooks, their recent search terms and the paths those searches were scoped to, and the paths of private assets they have open.
This report concerns FilterConfByPublishIgnore and its layout walker. It is distinct from the previously reported getConf issues, which concern configuration fields surviving HideConfSecret's blocklist. Restructuring the secret-masking path would not affect this, because UILayout is not a secret to be stripped. It is a field intended to be served and filtered.
Details
Route and writer asymmetry. kernel/api/router.go:70 registers POST /api/system/getConf with model.CheckAuth only, so it is reachable by the publish RoleReader token and anonymously when Publish.Auth.Enable is false. The corresponding writer, setUILayout at kernel/api/router.go:67, carries CheckAuth, CheckAdminRole and CheckReadonly. Only an administrator can write this state, and any reader can read it.
The filter exists and is intended to work. HideConfSecret never touches UILayout (zero matches on both refs). Instead the reader branch runs:
if model.IsReadOnlyRoleContext(c) {
publishIgnore := model.GetInvisiblePublishAccess(publishAccess)
maskedConf = model.FilterConfByPublishIgnore(publishIgnore, maskedConf)
}
FilterConfByPublishIgnore does exactly one thing, which is filter UILayout. The intent that readers must not see the administrator's private tabs is therefore already established in the code. The four defects below are failures of that filter, not an argument that it should exist.
filterLayoutItemByPublishIgnore is byte-identical at eef105683 and v3.7.4-alpha.1 and has not changed since 3facc37df (#16041).
Related Vulnerabilities
Other vulnerabilities affecting the same packages