Skip to content
This repository was archived by the owner on May 5, 2020. It is now read-only.

Conversation

haileys
Copy link

@haileys haileys commented May 9, 2014

This raises an exception if we're trying to render an action where the name includes /. While we initially thought 2.3 was not vulnerable, this has been shown to not be the case.

cc @github/dotcom-security

@ptoomey3
Copy link
Member

ptoomey3 commented May 9, 2014

👍 - As mentioned in chat...it looks like some logic assumes a / can exist within an action, but I'm fairly certain we don't rely on that. So long as unit tests are passing we can throw it out there and monitor for any wonkiness.

@haileys
Copy link
Author

haileys commented May 9, 2014

This is out in production now, watching for any strange exceptions. If it's all clear I'll merge this.

haileys pushed a commit that referenced this pull request May 9, 2014
@haileys haileys merged commit 7403667 into 2-3-github May 9, 2014
@haileys haileys deleted the 2-3-github+cve-2014-0130 branch May 9, 2014 14:52
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants