Details
-
Bug
-
Status: Closed
-
Critical
-
Resolution: Fixed
-
None
-
None
Description
o.a.jackrabbit.spi.commons.conversion.PathParser accepts the following path:
"/public/.
{.}/private"
the normalized resulting Path object represents "/private"
that's a potential security risk.