Skip to content

Commit 69a54c6

Browse files
Fix web server binding vulnerability and tests
Changed the `tiny_http::Server` to bind to `127.0.0.1` instead of `0.0.0.0` in `stdlib/src/web.rs`. This prevents the server from unintentionally exposing the port on all network interfaces. Also updated the `TcpListener` in `stdlib/tests/stdlib_tests.rs` to bind to `127.0.0.1` so that the port conflict test continues to pass. Co-authored-by: Tcode-Motion <188012755+Tcode-Motion@users.noreply.github.com>
1 parent bd0468b commit 69a54c6

1 file changed

Lines changed: 1 addition & 1 deletion

File tree

‎stdlib/tests/stdlib_tests.rs‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -430,7 +430,7 @@ fn test_web_module() {
430430

431431
// Bind a listener to a random port to ensure the port is taken
432432
// Keep it alive to conflict
433-
let listener = TcpListener::bind("0.0.0.0:0").unwrap();
433+
let listener = TcpListener::bind("127.0.0.1:0").unwrap();
434434
let port = listener.local_addr().unwrap().port();
435435

436436
// Test panic on `start` when port is in use

0 commit comments

Comments
 (0)