mirror of https://github.com/asterisk/asterisk
When using the ListCategories AMI action, it was possible to traverse upwards through the directories to files outside of the configured configuration directory. This action is now restricted to the configured directory and an error will now be returned if the specified file is outside of this limitation. Resolves: #GHSA-33x6-fj46-6rfh UserNote: The ListCategories AMI action now restricts files to the configured configuration directory.releases/certified-20.7
parent
5621b35ac3
commit
db0788cd35
Loading…
Reference in new issue