Comment 3 for bug 1998625

Revision history for this message
Aymeric Ducroquetz (aymericdu) wrote (last edit ): Re: Arbitrary file access through custom S3 XML entities

If it helps, we've already worked on the fix and the tests.
But we also thought about a way to detect this kind of attack.
Here is the commit attached.

Edited:
I forgot to add Romain De Joux as co-author of this patch. If you use this patch, is it possible to add him? Thanks
Co-Authored-By: Romain de Joux <email address hidden>