Closed yogthos closed 7 years ago
Currently, resource middleware doesn't ensure that the resource path is a child of the root path. So paths such as //../org/some-file could read files outside the resource path.
//../org/some-file
fixed by https://github.com/macchiato-framework/macchiato-core/commit/9aa41bcb9c839d40d2b2a412c3771bd84add143a
Currently, resource middleware doesn't ensure that the resource path is a child of the root path. So paths such as
//../org/some-file
could read files outside the resource path.