forked from orbit-oss/flask
fixed possible security problem in module branch
This commit is contained in:
parent
f1cde5bbfc
commit
8945a97a42
2 changed files with 22 additions and 1 deletions
|
|
@ -29,6 +29,7 @@ except ImportError:
|
|||
json_available = False
|
||||
|
||||
from werkzeug import Headers, wrap_file, is_resource_modified, cached_property
|
||||
from werkzeug.exceptions import NotFound
|
||||
|
||||
from jinja2 import FileSystemLoader
|
||||
|
||||
|
|
@ -334,7 +335,7 @@ class _PackageBoundObject(object):
|
|||
.. versionadded:: 0.5
|
||||
"""
|
||||
filename = posixpath.normpath(filename)
|
||||
if filename.startswith('../'):
|
||||
if filename.startswith(('/', '../')):
|
||||
raise NotFound()
|
||||
filename = os.path.join(self.root_path, 'static', filename)
|
||||
if not os.path.isfile(filename):
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue