Project

General

Profile

Actions

Bug #25217

closed

Additions to fileDenyPattern give security warning in BE

Added by Steffen Kamper about 13 years ago. Updated over 5 years ago.

Status:
Closed
Priority:
Should have
Category:
-
Target version:
-
Start date:
2011-03-01
Due date:
% Done:

0%

Estimated time:
TYPO3 Version:
4.5
PHP Version:
5.3
Tags:
Complexity:
Is Regression:
Sprint Focus:

Description

The check is wrong. Instead of checking if the entry is equal to default entry, it should check if any parts of the default value are removed.

As it's a security warning, this should be stated in the warning, so change the wording.

(issue imported from #M17817)


Files

17817.patch (2.82 KB) 17817.patch Administrator Admin, 2011-03-01 23:12
17817_v2.patch (4.34 KB) 17817_v2.patch Administrator Admin, 2011-03-02 00:00

Related issues 1 (0 open1 closed)

Has duplicate TYPO3 Core - Bug #18942: Warning on fileDenyPattern is always shown although it's safeClosedChris topher2008-06-12

Actions
Actions #1

Updated by Daniel Minder about 13 years ago

Since my original report 8690 is now marked as resolved although this bug is only assigned I have to add it here as well:
The reports sysext also includes the same check in class.tx_reports_reports_status_securitystatus.php. So, it should also be modified there.

Actions #2

Updated by Steffen Kamper about 13 years ago

thanks for the hint, i will add it there too.

Actions #3

Updated by Steffen Kamper about 13 years ago

v2 also change reports module.

Actions #5

Updated by Andreas Wolf about 13 years ago

Merged to master in 68a0fa92d7abc01b92ddd4ee09ae19845e09f7b3.

Actions #6

Updated by Susanne Moog about 13 years ago

  • Target version deleted (4.5.3)
Actions #7

Updated by Benni Mack over 5 years ago

  • Status changed from Resolved to Closed
Actions

Also available in: Atom PDF