Security update to the @apostrophecms/import-export module #4405
boutell
announced in
Release Notes
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
In version 1.2.1, we have fixed a security issue that allowed a correctly crafted
HTTP request to delete arbitrary files and folders, subject to the permissions with which the Node.js process was run. No user account was required to exploit this issue.
All users of this module should immediately run
npm update @apostrophecms/import-export
and deploy the latest version of this module. The module has been carefully audited for similar issues and best practices have been put in place to prevent any similar issue in future.Beta Was this translation helpful? Give feedback.
All reactions