passbolt / go-passbolt

A Go Library to interact with Passbolt, the open source password manager for teams!
https://passbolt.com
MIT License
25 stars 7 forks source link

PBL-06-012: "URL path traversal via command line flags" #10

Closed speatzle closed 2 years ago

speatzle commented 2 years ago

All ID's that are given to the SDK as a string should be checked whether they are a valid UUID to prevent potential security issues.

speatzle commented 2 years ago

fixed with f1122a019c4f2c6f0e21fca78835f2a967488df5 released in v0.5.3