Skip to content
GitLab
Explore
Sign in
Primary navigation
Search or go to…
Project
V
vitamui-pr-pastis
Manage
Activity
Members
Labels
Code
Merge requests
1
Repository
Branches
Commits
Tags
Repository graph
Compare revisions
Build
Pipelines
Jobs
Pipeline schedules
Artifacts
Deploy
Releases
Package Registry
Operate
Environments
Terraform modules
Analyze
Value stream analytics
Contributor analytics
CI/CD analytics
Repository analytics
Help
Help
Support
GitLab documentation
Compare GitLab plans
Community forum
Contribute to GitLab
Provide feedback
Keyboard shortcuts
?
Snippets
Groups
Projects
Show more breadcrumbs
dad
vitamui-pr-pastis
Commits
ba83d1a3
Commit
ba83d1a3
authored
4 years ago
by
Makhtar DIAGNE
Browse files
Options
Downloads
Patches
Plain Diff
[FIX RABB-808] Fix directory traversal security issue on getLogo
parent
710c9371
No related branches found
No related tags found
No related merge requests found
Changes
1
Hide whitespace changes
Inline
Side-by-side
Showing
1 changed file
ui/ui-commons/src/main/java/fr/gouv/vitamui/ui/commons/service/ApplicationService.java
+1
-1
1 addition, 1 deletion
...r/gouv/vitamui/ui/commons/service/ApplicationService.java
with
1 addition
and
1 deletion
ui/ui-commons/src/main/java/fr/gouv/vitamui/ui/commons/service/ApplicationService.java
+
1
−
1
View file @
ba83d1a3
...
...
@@ -163,7 +163,7 @@ public class ApplicationService extends AbstractCrudService<ApplicationDto> {
}
public
String
getBase64File
(
String
fileName
,
String
basePath
)
{
final
Path
assetFile
=
Paths
.
get
(
basePath
,
fileName
).
normalize
(
);
final
Path
assetFile
=
Paths
.
get
(
basePath
,
Paths
.
get
(
fileName
).
getFileName
().
toString
()
);
String
base64Asset
=
null
;
try
{
base64Asset
=
DatatypeConverter
.
printBase64Binary
(
Files
.
readAllBytes
(
assetFile
));
...
...
This diff is collapsed.
Click to expand it.
Preview
0%
Try again
or
attach a new file
.
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Save comment
Cancel
Please
register
or
sign in
to comment