Merge r24393 from trunk to 5.1-stable (#43690).

git-svn-id: https://svn.redmine.org/redmine/branches/5.1-stable@24474 e93f8b46-1217-0410-a6f0-8f06a7374b81
This commit is contained in:
Marius Balteanu
2026-03-05 02:26:09 +00:00
parent bae943db12
commit c361541f5c

View File

@@ -112,7 +112,7 @@ module Redmine
# Here we do not shell-out, so we do not want quotes.
def target(path=nil)
# Prevent the use of ..
if path and !/(^|\/)\.\.(\/|$)/.match?(path)
if path and !/(^|[\/\\])\.\.([\/\\]|$)/.match?(path)
return "#{self.url}#{without_leading_slash(path)}"
end