[
https://issues.apache.org/jira/browse/OFBIZ-12080?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17245449#comment-17245449 ]
ASF subversion and git services commented on OFBIZ-12080:
---------------------------------------------------------
Commit 4481f373ca45514c1e6fb86f1f1d2c6204f7a65a in ofbiz-framework's branch refs/heads/trunk from Jacques Le Roux
[
https://gitbox.apache.org/repos/asf?p=ofbiz-framework.git;h=4481f37 ]
Fixed: Secure the uploads (OFBIZ-12080)
Handles audio and video formats supported by Tika.
Adds few new audio and video formats in seed data.
AFAIK there are no ways to embed a webshell in an audio or video file. So I did
not sophisticate the validation, just rely on Tika.
I have also fixed bugs in SecuredUpload: in isValidSvgFile and
isValidImageIncludingSvgFile
--
This message was sent by Atlassian Jira
(v8.3.4#803005)