turquoiseowl / i18n

Smart internationalization for ASP.NET
Other
556 stars 155 forks source link

Security vulnerability crashes app pool #387

Closed Hangarspace closed 4 years ago

Hangarspace commented 5 years ago

@turquoiseowl

During some penetration testing of our application, the testers have found a security vulnerability in the i18n library that potentially crashes the app pool.

I have a fix, but not the contribution rights and presumably its not a great idea to describe the issue in too much detail in public lest somebody decides to hijack this vulnerability.

turquoiseowl commented 5 years ago

Thanks for this. New version 2.1.15 including your fix just released to NuGet.