Data Flow Sanitation Issue Fix
Package
Affected versions
< 19.4.15
>= 20.0.0, < 20.0.13
Patched versions
19.4.15
20.0.13
Description
Published by the National Vulnerability Database
Aug 27, 2021
Reviewed
Aug 30, 2021
Published to the GitHub Advisory Database
Aug 30, 2021
Last updated
Feb 1, 2023
Impact
Due to missing sanitation in data flow it was possible for admin users to upload arbitrary executable files to the server.
References