mirror of https://github.com/asterisk/asterisk
When using the ListCategories AMI action, it was possible to traverse upwards through the directories to files outside of the configured configuration directory. This action is now restricted to the configured directory and an error will now be returned if the specified file is outside of this limitation. Resolves: #GHSA-33x6-fj46-6rfh UserNote: The ListCategories AMI action now restricts files to the configured configuration directory.pull/1053/head
parent
e904ae5df0
commit
7f70190c59
Loading…
Reference in new issue