Quantcast
Channel: Issues for Drupal core
Viewing all articles
Browse latest Browse all 299521

\Drupal\file\Plugin\rest\resource\FileUploadResource uses basename() when it needs to use the Drupal version

$
0
0

Problem/Motivation

\Drupal\file\Plugin\rest\resource\FileUploadResource is using PHP's builtin basename() which is vulnerable to https://bugs.php.net/bug.php?id=77239

Proposed resolution

Use \Drupal\Core\File\FileSystem::basename() instead and add test coverage.

Remaining tasks

User interface changes

none

API changes

none

Data model changes

none

Release notes snippet

n/a


Viewing all articles
Browse latest Browse all 299521

Latest Images

Trending Articles



Latest Images

<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>