angler-fishThe Vulnerability History Project

[1.4.x] Prevented arbitrary file inclusion with {% ssi %} tag and relative paths.

      Thanks Rainer Koirikivi for the report and draft patch.

This is a security fix; disclosure to follow shortly.

Backport of 7fe5b656c9 from master
    
commit 87d2750b39f6f2d54b7047225521a44dcd37e896
-2
-31
expand_less