Skip to content

[GWC-1210] Improve input validation in ByteStreamController#1211

Merged
smithkm merged 1 commit intoGeoWebCache:mainfrom
sikeoka:GWC-1210
Feb 2, 2024
Merged

[GWC-1210] Improve input validation in ByteStreamController#1211
smithkm merged 1 commit intoGeoWebCache:mainfrom
sikeoka:GWC-1210

Conversation

@sikeoka
Copy link
Copy Markdown
Contributor

@sikeoka sikeoka commented Feb 1, 2024

This PR updates ByteStreamController to prevent using backslash characters on Windows to traverse directories. This PR also removes double decoding of the URL path which can be used to bypass other URL checking.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants