Skip to content

Conversation

amusarra
Copy link
Member

@amusarra amusarra commented Feb 9, 2024

PR per nuova release 2.2.1 che contiene le seguenti fix.

Fixed

  • CWE-23: Relative Path Traversal
  • CWE-643: Improper Neutralization of Data within XPath Expressions ('XPath Injection')
  • CWE-611: Improper Restriction of XML External Entity Reference ('XXE')
  • SC2086: Double quote to prevent globbing and word splitting
  • SC2129: Consider using { cmd1; cmd2; } >> file instead of individual redirects

@amusarra amusarra merged commit 8f7cccf into master Feb 9, 2024
@amusarra amusarra deleted the security/fix-code-sec-vulnerabilities branch February 9, 2024 18:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant