[
https://issues.apache.org/jira/browse/OFBIZ-12080?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17248928#comment-17248928 ]
ASF subversion and git services commented on OFBIZ-12080:
---------------------------------------------------------
Commit 00d875251c94496b198ef4fdad61f42fd8318727 in ofbiz-framework's branch refs/heads/release17.12 from Jacques Le Roux
[
https://gitbox.apache.org/repos/asf?p=ofbiz-framework.git;h=00d8752 ]
Fixed: Secure the uploads (OFBIZ-12080)
Prevents too long filenames as recommended by OWASP.
Based on
https://security.stackexchange.com/questions/46484/denial-of-service-when-uploading-a-file#answer-46495I decided to not limit sizes of files. Anyway we know it's only post-auth...
--
This message was sent by Atlassian Jira
(v8.3.4#803005)