Insecure CSV upload #20

Closed
opened 2021-04-03 22:59:47 +02:00 by nik · 5 comments
nik commented 2021-04-03 22:59:47 +02:00 (Migrated from edugit.org)

CSV fiels are uploaded to the default media storage without any authentication.

Filenames are replaced with a random UUID, but that is not enoughto protect such sensitive information.

CSV fiels are uploaded to the default media storage without any authentication. Filenames are replaced with a random UUID, but that is not enoughto protect such sensitive information.
nik commented 2021-04-05 12:07:11 +02:00 (Migrated from edugit.org)

changed due date to April 15, 2021

changed due date to April 15, 2021
nik commented 2021-05-15 19:03:18 +02:00 (Migrated from edugit.org)

made the issue visible to everyone

made the issue visible to everyone
hansegucker commented 2021-05-18 16:42:20 +02:00 (Migrated from edugit.org)

created merge request !115 to address this issue

created merge request !115 to address this issue
hansegucker commented 2021-05-18 16:42:20 +02:00 (Migrated from edugit.org)

mentioned in merge request !115

mentioned in merge request !115
nik commented 2021-05-18 22:39:38 +02:00 (Migrated from edugit.org)

assigned to @hansegucker

assigned to @hansegucker
nik (Migrated from edugit.org) closed this issue 2021-05-20 13:05:46 +02:00
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
aleksis/AlekSIS-App-CSVImport#20
No description provided.