Actions
Architecture #27402
openWe need to resolve directory real path in our path trasversal check
Fix check:
To do
Regression:
No
Description
In #26957 and related ticket, we added some tooling to avoid that a file resolution escape a parent folder.
But the parent folder isn't resoleved to its real path, which means that if it is a linked to some directory, then the sanitize function is always failing.
Updated by François ARMAND 4 days ago
- Status changed from In progress to Pending technical review
- Assignee changed from François ARMAND to Clark ANDRIANASOLO
- Pull Request set to https://github.com/Normation/rudder/pull/6558
Updated by Anonymous 4 days ago
- Status changed from Pending technical review to Pending release
Applied in changeset rudder|14a06fc676f7736a5ad6d09a9b614327414234fa.
Actions