VirtualBox

Opened 14 months ago

Last modified 2 months ago

#21809 new defect

Unshared Folder Seems Accessible via Symbolic Links — at Initial Version

Reported by: hit1t Owned by:
Component: shared folders Version: VirtualBox-6.1.44
Keywords: Cc: hit1t
Guest type: Windows Host type: Linux

Description

Hi there,

I wanted to discuss something that has caught my attention and might need a bit of assistance. It's related to security, and I believe we've stumbled upon a minor hiccup. Here's what I've observed:

Shared Folder: /home/hit1t/Desktop/OnlySharedFolder

Test Folder: /home/hit1t/test

To provide you with a complete picture, I established a symbolic link to the Test Folder on my Desktop using this command:

ln -s /home/hit1t/test ~/Desktop/test

Now, here comes the interesting part: When I moved this linked folder to the shared directory, it surprisingly allowed access to the 'Test' folder from the Guest OS. This caught my attention because it has the potential to allow users access to information that hasn't been explicitly shared, which could inadvertently compromise security.

Wondering your thoughts on this, thanks

Change History (0)

Note: See TracTickets for help on using tickets.

© 2024 Oracle Support Privacy / Do Not Sell My Info Terms of Use Trademark Policy Automated Access Etiquette