Uh oh!
There was an error while loading.Please reload this page.
- Notifications
You must be signed in to change notification settings - Fork938
Commit64ebb9f
committed
This change adds a check during reference resolving to see if itcontains an up-level reference ('..'). If it does, it raises anexception.This fixesCVE-2023-41040, which allows an attacker to access filesoutside the repository's directory.
1 parent91b464c commit64ebb9f
1 file changed
+2
-0
lines changedLines changed: 2 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
168 | 168 |
| |
169 | 169 |
| |
170 | 170 |
| |
| 171 | + | |
| 172 | + | |
171 | 173 |
| |
172 | 174 |
| |
173 | 175 |
| |
|
0 commit comments
Comments
(0)