[jira] [Closed] (OFBIZ-12055) Prevent possible post-auth RCE from webtools/control/ProgramExport

2020-11-14 Thread Jacques Le Roux (Jira)


 [ 
https://issues.apache.org/jira/browse/OFBIZ-12055?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Jacques Le Roux closed OFBIZ-12055.
---
Fix Version/s: (was: Upcoming Branch)
   17.12.05
   18.12.01
   Resolution: Fixed

> Prevent possible post-auth RCE from webtools/control/ProgramExport
> --
>
> Key: OFBIZ-12055
> URL: https://issues.apache.org/jira/browse/OFBIZ-12055
> Project: OFBiz
>  Issue Type: Sub-task
>  Components: framework/webtools
>Affects Versions: Trunk
>Reporter: Jacques Le Roux
>Assignee: Jacques Le Roux
>Priority: Minor
> Fix For: 18.12.01, 17.12.05
>
>
> This was reported to the security team by Shuibo Ye . We 
> did not create a CVE because it's a post-auth "vulnerability"



--
This message was sent by Atlassian Jira
(v8.3.4#803005)


[jira] [Closed] (OFBIZ-12055) Prevent possible post-auth RCE from webtools/control/ProgramExport

2020-11-13 Thread Jacques Le Roux (Jira)


 [ 
https://issues.apache.org/jira/browse/OFBIZ-12055?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Jacques Le Roux closed OFBIZ-12055.
---
Resolution: Implemented

> Prevent possible post-auth RCE from webtools/control/ProgramExport
> --
>
> Key: OFBIZ-12055
> URL: https://issues.apache.org/jira/browse/OFBIZ-12055
> Project: OFBiz
>  Issue Type: Improvement
>  Components: framework/webtools
>Affects Versions: Trunk
>Reporter: Jacques Le Roux
>Assignee: Jacques Le Roux
>Priority: Minor
> Fix For: Upcoming Branch
>
>
> This was reported to the security team by Shuibo Ye . We 
> did not create a CVE because it's a post-auth "vulnerability"



--
This message was sent by Atlassian Jira
(v8.3.4#803005)