Mandriva Linux Security Advisory 2014-235

Mandriva Linux Security Advisory 2014-235 – Plack::App::File would previously strip trailing slashes off provided paths. This in combination with the common pattern of serving files with Plack::Middleware::Static could allow an attacker to bypass a whitelist of generated files.

Leave a Reply