Skip to content

Conversation

@dankenigsberg
Copy link
Contributor

With this change, the tweaked example shows how an attacker can make the code read from an unsafe path by adding .. to their path.

Signed-off-by: Dan Kenigsberg danken@redhat.com

With this change, the tweaked example shows how an attacker can make the code read from an unsafe path by adding `..` to their path.

Signed-off-by: Dan Kenigsberg <danken@redhat.com>
@dankenigsberg
Copy link
Contributor Author

/cc @Aisuko

@ccojocar ccojocar merged commit d50895c into securego:master Dec 29, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants