Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix(security): freemarker SSTI vulnerability. #1402

Merged
merged 1 commit into from
Jun 20, 2021

Conversation

ruibaby
Copy link
Member

@ruibaby ruibaby commented Jun 20, 2021

避免使用 ?new 内建函数来执行一些不安全的类方法。

@ruibaby ruibaby added the vulnerability Vulnerability label Jun 20, 2021
@ruibaby ruibaby added this to the 1.4.9 milestone Jun 20, 2021
@ruibaby ruibaby self-assigned this Jun 20, 2021
@ruibaby ruibaby merged commit 5539cf1 into halo-dev:master Jun 20, 2021
@ruibaby ruibaby deleted the fix/freemarker-SSTI-vulnerability branch June 20, 2021 08:35
eucham pushed a commit to eucham/halo that referenced this pull request Jun 27, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
vulnerability Vulnerability
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants