Skip to content

security question, fix arbitrary file read#3383

Merged
astaxie merged 1 commit intobeego:developfrom
LockGit:develop
Nov 8, 2018
Merged

security question, fix arbitrary file read#3383
astaxie merged 1 commit intobeego:developfrom
LockGit:develop

Conversation

@LockGit
Copy link
Copy Markdown
Contributor

@LockGit LockGit commented Nov 7, 2018

When use file type session in the beego framework,Hacker can use "../" modify the sessionID value,

Then directory crossing read any file , So I think beego should check the sessionID before read it.

Some example:

1,https://www.anquanke.com/post/id/163575

2,gogs/gogs#5469

@astaxie astaxie merged commit 8391d26 into beego:develop Nov 8, 2018
@DennisMao DennisMao mentioned this pull request Sep 8, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants