[
https://issues.apache.org/jira/browse/OFBIZ-12080?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17248929#comment-17248929 ]
ASF subversion and git services commented on OFBIZ-12080:
---------------------------------------------------------
Commit b159dffb15c36daa2d3d1f3a622734c681a0c21e in ofbiz-framework's branch refs/heads/release18.12 from Jacques Le Roux
[
https://gitbox.apache.org/repos/asf?p=ofbiz-framework.git;h=b159dff ]
Fixed: Secure the uploads (OFBIZ-12080)
Prevents too long filenames as recommended by OWASP.
Based on
https://security.stackexchange.com/questions/46484/denial-of-service-when-uploading-a-file#answer-46495I decided to not limit sizes of files. Anyway we know it's only post-auth...
--
This message was sent by Atlassian Jira
(v8.3.4#803005)