Explorar o código

#3461 fix security issue of REAMDE path in create repository

Unknwon %!s(int64=8) %!d(string=hai) anos
pai
achega
cc647ba9d5
Modificáronse 1 ficheiros con 1 adicións e 1 borrados
  1. 1 1
      models/repo.go

+ 1 - 1
models/repo.go

@@ -870,7 +870,7 @@ type CreateRepoOptions struct {
 }
 
 func getRepoInitFile(tp, name string) ([]byte, error) {
-	relPath := path.Join("conf", tp, name)
+	relPath := path.Join("conf", tp, strings.TrimLeft(name, "./"))
 
 	// Use custom file when available.
 	customPath := path.Join(setting.CustomPath, relPath)