[
https://issues.apache.org/jira/browse/OFBIZ-12080?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17245364#comment-17245364 ]
ASF subversion and git services commented on OFBIZ-12080:
---------------------------------------------------------
Commit 7ff8fb814e6ab5fed1fba39764f19b55ac4c4c05 in ofbiz-framework's branch refs/heads/release17.12 from Jacques Le Roux
[
https://gitbox.apache.org/repos/asf?p=ofbiz-framework.git;h=7ff8fb8 ]
Fixed: Secure the uploads (OFBIZ-12080)
Handles audio and video formats supported by Tika.
Adds few new audio and video formats in seed data.
AFAIK there are no ways to embed a webshell in an audio or video file. So I did
not sophisticate the validation, just rely on Tika.
I have also fixed bugs in SecuredUpload: in isValidSvgFile and
isValidImageIncludingSvgFile
--
This message was sent by Atlassian Jira
(v8.3.4#803005)