[
https://issues.apache.org/jira/browse/OFBIZ-12080?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17248930#comment-17248930 ]
ASF subversion and git services commented on OFBIZ-12080:
---------------------------------------------------------
Commit 63e2b526b84442eace3bbecafc4b12f8aeaf141d in ofbiz-framework's branch refs/heads/trunk from Jacques Le Roux
[
https://gitbox.apache.org/repos/asf?p=ofbiz-framework.git;h=63e2b52 ]
Fixed: Secure the uploads (OFBIZ-12080)
Prevents too long filenames as recommended by OWASP.
Based on
https://security.stackexchange.com/questions/46484/denial-of-service-when-uploading-a-file#answer-46495I decided to not limit sizes of files. Anyway we know it's only post-auth...
--
This message was sent by Atlassian Jira
(v8.3.4#803005)