Skip to content

Commit 179da58

Browse files
committed
Documented security fix in changelog
1 parent aeed530 commit 179da58

File tree

1 file changed

+3
-0
lines changed

1 file changed

+3
-0
lines changed

CHANGES

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -15,6 +15,9 @@ Bugfix release, release date to be announced.
1515
module setups.
1616
- Fixed an issue where the subdomain setting for modules was
1717
ignored for the static folder.
18+
- Fixed a security problem that allowed clients to download arbitrary files
19+
if the host server was a windows based operating system and the client
20+
uses backslashes to escape the directory the files where exposed from.
1821

1922
Version 0.6
2023
-----------

0 commit comments

Comments
 (0)