mirror of https://github.com/asterisk/asterisk
When using the ListCategories AMI action, it was possible to traverse upwards through the directories to files outside of the configured configuration directory. This action is now restricted to the configured directory and an error will now be returned if the specified file is outside of this limitation. Resolves: #GHSA-33x6-fj46-6rfh UserNote: The ListCategories AMI action now restricts files to the configured configuration directory.pull/1432/head
parent
6b3dadfbe2
commit
e358ce0762
Loading…
Reference in new issue