Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
[SECURITY] Disallow access to fallback storage '0'
All users with access to the filelist module are able to display the content of the document root folder by spoofing the url. This patch prevents any rendering from that storage and throws an error. Resolves: #67538 Releases: master, 6.2 Security-Bulletin: TYPO3-CORE-SA-2015-005 Change-Id: Ia503c572e550aaa3e74ffbaf3da87796ad04723a Reviewed-on: http://review.typo3.org/40815 Reviewed-by: Helmut Hummel <helmut.hummel@typo3.org> Tested-by: Helmut Hummel <helmut.hummel@typo3.org> Reviewed-by: Benjamin Mack <benni@typo3.org> Tested-by: Benjamin Mack <benni@typo3.org>
- Loading branch information