From 3ba089ac7e5720a363d01499451bcfa8c74a56d9 Mon Sep 17 00:00:00 2001 From: Mariusz Felisiak Date: Wed, 12 May 2021 10:42:01 +0200 Subject: [PATCH] [2.2.x] Refs #32718 -- Corrected CVE-2021-31542 release notes. Backport of d1f1417caed648db2f81a1ec28c47bf958c01958 from main. --- docs/releases/2.2.21.txt | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/docs/releases/2.2.21.txt b/docs/releases/2.2.21.txt index f32aeadff7..2302df4285 100644 --- a/docs/releases/2.2.21.txt +++ b/docs/releases/2.2.21.txt @@ -13,5 +13,4 @@ CVE-2021-31542: Potential directory-traversal via uploaded files directory-traversal via uploaded files with suitably crafted file names. In order to mitigate this risk, stricter basename and path sanitation is now -applied. Specifically, empty file names and paths with dot segments will be -rejected. +applied.