https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=41932

--- Comment #56 from Marcel de Rooy <[email protected]> ---
(In reply to David Cook from comment #55)
> (In reply to Marcel de Rooy from comment #54)
> > (In reply to David Cook from comment #40)
> > > Upon review... the code is not very easy to read at all and I think it 
> > > might
> > > not validate/sanitize the inputs enough, although I haven't done a 
> > > practical
> > > check yet. We want to be careful when it comes to regex inputs. I wish we
> > > hadn't added regex to other parts of Koha because it's a nightmare to 
> > > secure.
> > 
> > I removed the regex feature. Altough I think that matching only should not
> > be a nightmare..
> 
> I'm not sure if you saw my message on Mattermost, but I've tried Regular
> Expression Denial of Service (ReDoS) with Perl using payloads and strategies
> outlined by folk like OWASP, and I can't get Perl to break. 
> 
> So while there may be a theoretical problem with match inputs... I think in
> practice it's OK. So if you did want to include the regex I think it would
> be OK.
> 
> Sorry for the run around on this one!

Lets gp with the current set of patches now. Time to get this moving..

-- 
You are receiving this mail because:
You are watching all bug changes.
_______________________________________________
Koha-bugs mailing list -- [email protected]
To unsubscribe send an email to [email protected]
website : http://www.koha-community.org/
git : http://git.koha-community.org/
bugs : http://bugs.koha-community.org/

Reply via email to