angler-fishThe Vulnerability History Project

[1.5.x] Prevented arbitrary file inclusion with {% ssi %} tag and relative paths.

      Thanks Rainer Koirikivi for the report and draft patch.

This is a security fix; disclosure to follow shortly.

Backport of 7fe5b656c9 from master
    
commit 988b61c550d798f9a66d17ee0511fb7a9a7f33ca
-2
-31
expand_less