You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Is your feature request related to a problem? Please describe.
When importing the configuration file, the imported file itself and the file format inside the zip package are not checked. In the interface where other users can upload files, the file format is not verified. This can cause unsafe file types to pass in.
导入配置文件的时候,未对导入的文件本身以及zip包内部的文件格式做校验。在其他用户可以上传文件的接口中,也未校验文件格式。这可能导致不安全的文件类型传入。
Describe the solution you'd like
根据白名单对文件格式作过滤
Describe alternatives you've considered
Additional context
config module
配置中心模块
The text was updated successfully, but these errors were encountered:
Is your feature request related to a problem? Please describe.
When importing the configuration file, the imported file itself and the file format inside the zip package are not checked. In the interface where other users can upload files, the file format is not verified. This can cause unsafe file types to pass in.
导入配置文件的时候,未对导入的文件本身以及zip包内部的文件格式做校验。在其他用户可以上传文件的接口中,也未校验文件格式。这可能导致不安全的文件类型传入。
Describe the solution you'd like
根据白名单对文件格式作过滤
Describe alternatives you've considered
Additional context
config module
配置中心模块
The text was updated successfully, but these errors were encountered: