Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerability with high severity on nuget.org #68

Open
commect opened this issue Sep 28, 2021 · 2 comments
Open

Vulnerability with high severity on nuget.org #68

commect opened this issue Sep 28, 2021 · 2 comments

Comments

@commect
Copy link

commect commented Sep 28, 2021

Thanks for the great work!
When will you remove vulnerability with high severity. According to information on the website:
https://www.nuget.org/packages/elFinder.NetCore/

@commect commect changed the title nuget.org Vulnerability with high severity on nuget.org Sep 28, 2021
@trannamtrung1st
Copy link
Contributor

@gordon-matt
Really want to help, but this is non-trivial work to do. The idea is that we should sanitize the file name every time we combine paths using Path.Combine. We must also make changes to the extract command handler. This will require many changes and regression testing.
I've been busy recently and still have not had the time to work on it yet.

@gordon-matt
Copy link
Owner

gordon-matt commented Nov 1, 2021

@trannamtrung1st No problem. You have done a lot already.. Let someone else take this, if they wish. Otherwise, I will try to see to this at some point in future.

@commect If you wish to do the coding changes, raise a PR and I will be happy to review it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants