Skip to content
This repository has been archived by the owner on May 1, 2023. It is now read-only.

release-3b74e707: address path traversal vulnerability

Compare
Choose a tag to compare
@kacasey8 kacasey8 released this 23 Feb 15:44
Summary: Address vulnerability task as per the suggested fix. Also address a bug in the previously reverted diff D33633205 (https://github.com/facebookincubator/profilo/commit/62b922a1a4c7530c2dc9b4e6a34d48cb20b8f355), by comparing canonical path substrings instead of the directory name.

Reviewed By: yanivsb

Differential Revision: D34415536

fbshipit-source-id: 60d8edea45d0b80429c5e008182e9abf951e137f