mirror of
https://github.com/redmine/redmine.git
synced 2026-05-07 01:07:24 +02:00
Merge r24393 from trunk to 6.1-stable (#43690).
git-svn-id: https://svn.redmine.org/redmine/branches/6.1-stable@24395 e93f8b46-1217-0410-a6f0-8f06a7374b81
This commit is contained in:
@@ -111,7 +111,7 @@ module Redmine
|
||||
# Here we do not shell-out, so we do not want quotes.
|
||||
def target(path=nil)
|
||||
# Prevent the use of ..
|
||||
if path and !/(^|\/)\.\.(\/|$)/.match?(path)
|
||||
if path and !/(^|[\/\\])\.\.([\/\\]|$)/.match?(path)
|
||||
return "#{self.url}#{without_leading_slash(path)}"
|
||||
end
|
||||
|
||||
|
||||
Reference in New Issue
Block a user