mirror of
https://github.com/TryGhost/Ghost.git
synced 2024-12-19 00:11:49 +03:00
378dd913aa
refs https://github.com/TryGhost/Team/issues/2843 - Using encoded path traversal characters in URL's path allowed to fetch any file within active theme's folder, which is disallowed - credits to: fuomag9 https://kiwi.fuo.fi/@fuomag9 |
||
---|---|---|
.. | ||
apps | ||
helpers | ||
meta | ||
services | ||
utils | ||
web/middleware |