Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE: Fix Receiver malicious tenant #5969

Merged
merged 1 commit into from
Jan 30, 2023

Commits on Jan 29, 2023

  1. CVE: Fix Receiver malicious tenant

    If running as root or with enough privileges, receiver can create a
    directory outside of the configured TenantHeader.
    
    This commit fixes it up by sanitizing the user input and explicity not
    allowing such behavior.
    
    Signed-off-by: Daniel Mellado <dmellado@redhat.com>
    danielmellado committed Jan 29, 2023
    Configuration menu
    Copy the full SHA
    74d2560 View commit details
    Browse the repository at this point in the history