CVE-2019-17352: Unrestricted Upload of File with Dangerous Type
(updated )
In JFinal cos before, there is a vulnerability that can bypass the isSafeFile()
function: one can upload any type of file. For example, a .jsp file may be stored and almost immediately deleted, but this deletion step does not occur for certain exceptions.
References
Detect and mitigate CVE-2019-17352 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →