8000 More security fixes by carakas · Pull Request #3137 · forkcms/forkcms · GitHub
[go: up one dir, main page]

Skip to content
< 8000 div style="--spacing:var(--spacing-none)" class="prc-PageLayout-PageLayoutRoot--KH-d" data-has-sidebar="true">

More security fixes#3137

Merged
carakas merged 29 commits intoforkcms:masterfrom
justcarakas:more-security-fixes
Jul 2, 2020
Merged

More security fixes#3137
carakas merged 29 commits intoforkcms:masterfrom
justcarakas:more-security-fixes

Conversation

@carakas
Copy link
Member
@carakas carakas commented Jun 26, 2020

Type

  • Security

Resolves the following issues

My mailbox overflowing by pen testers that all report a different variant of the same issue

Pull request description

First of all, this is not a huge security issue as long as the people that have access to the backend can be trusted.
But since you never know when you have somebody trying out some nasty stuff or using an unsafe password and someone else gains access to an account with a limited set of rights this PR will prevent them from trying to steal admin passwords or executing code as a different user through stored xss

Also changed the default of serialised data not allowing any classes in it since it can be abused as well

carakas added 26 commits June 8, 2020 07:55
@carakas carakas added the security Pull requests that address a security vulnerability label Jun 26, 2020
@carakas carakas added this to the 5.8.3 milestone Jun 26, 2020
@carakas carakas requested a review from a team as a code owner June 26, 2020 23:53
@carakas carakas changed the title More security fixes [WIP] More security fixes Jun 27, 2020
@carakas carakas marked this pull request as draft June 27, 2020 00:23
@carakas carakas changed the title [WIP] More security fixes More security fixes Jun 27, 2020
@carakas carakas force-pushed the more-security-fixes branch from 04d6bed to 2e13cf4 Compare June 27, 2020 00:27
@carakas carakas marked this pull request as ready for review June 30, 2020 16:04
@carakas carakas merged commit ad99512 into forkcms:master Jul 2, 2020
@carakas carakas deleted the more-security-fixes branch July 2, 2020 18:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

security Pull requests that address a security vulnerability

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

0