mirror of https://github.com/asterisk/asterisk
When using the ListCategories AMI action, it was possible to traverse upwards through the directories to files outside of the configured configuration directory. This action is now restricted to the configured directory and an error will now be returned if the specified file is outside of this limitation. Resolves: #GHSA-33x6-fj46-6rfh UserNote: The ListCategories AMI action now restricts files to the configured configuration directory.releases/22.4
parent
a66c9decfe
commit
4d80d7ab22
Loading…
Reference in new issue