Skip to content

[Bug] File observables with special character in name can not be downloaded #1842

Closed
@KaanSK

Description

@KaanSK

Work Environment

Question Answer
OS version (server) Ubuntu docker base image
OS version (client) All ...
TheHive version / git hash 4.0.5
Package Type DEB
Browser type & version All

Problem Description

File observables with special characters in filenames can not be downloaded. "Invalid filename" error is shown. File can be found in server filesystem.

Steps to Reproduce

  1. Create a file observable with example name: "Re: Re: malicious mail.eml"
  2. Try to download zipped file from TheHive UI
  3. Observe the error

Possible Solutions

  1. Filenaming logic (mapping filename to file) may be investigated
  2. Validations could be added on frontend and backend
  3. Special chars and whitespace could be stripped

Metadata

Metadata

Assignees

Labels

TheHive4TheHive4 related issuesbug

Type

No type

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions