69645389e9
The API permits path traversal characters like '../' to be passed down to the template finder. Detect these requests and cause them to fail with a 500 response code. |
||
---|---|---|
.. | ||
finders | ||
base_template.rb | ||
dockerfile_template.rb | ||
gitignore_template.rb | ||
gitlab_ci_yml_template.rb | ||
issue_template.rb | ||
merge_request_template.rb |