Insecure CSV upload #20

Closed
opened 2021-04-03 22:59:47 +02:00 by nik · 5 comments
Owner

CSV fiels are uploaded to the default media storage without any authentication.

Filenames are replaced with a random UUID, but that is not enoughto protect such sensitive information.

CSV fiels are uploaded to the default media storage without any authentication. Filenames are replaced with a random UUID, but that is not enoughto protect such sensitive information.
Author
Owner

changed due date to April 15, 2021

changed due date to April 15, 2021
Author
Owner

made the issue visible to everyone

made the issue visible to everyone
Owner

created merge request !115 to address this issue

created merge request !115 to address this issue
Owner

mentioned in merge request !115

mentioned in merge request !115
Author
Owner

assigned to @hansegucker

assigned to @hansegucker
nik closed this issue 2021-05-20 13:05:46 +02:00
Sign in to join this conversation.
No milestone
No project
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
aleksis/AlekSIS-App-CSVImport#20
No description provided.