69645389e9
The API permits path traversal characters like '../' to be passed down to the template finder. Detect these requests and cause them to fail with a 500 response code.
5 lines
106 B
YAML
5 lines
106 B
YAML
---
|
|
title: Prevent a path traversal attack on global file templates
|
|
merge_request:
|
|
author:
|
|
type: security
|