diff options
| author | John MacFarlane <jgm@berkeley.edu> | 2023-06-20 13:50:13 -0700 |
|---|---|---|
| committer | John MacFarlane <jgm@berkeley.edu> | 2023-06-20 13:50:13 -0700 |
| commit | 5e381e3878b5da87ee7542f7e51c3c1a7fd84b89 (patch) | |
| tree | b15e9d06c07398ab328bde56e7720c52fafe5f80 /stack.yaml | |
| parent | 40dacad52581c785c022d42bf7117216dcfe915a (diff) | |
Fix a security vulnerability in MediaBag and T.P.Class.IO.writeMedia.
This vulnerability, discovered by Entroy C, allows users to write
arbitrary files to any location by feeding pandoc a specially crafted
URL in an image element. The vulnerability is serious for anyone
using pandoc to process untrusted input. The vulnerability does
not affect pandoc when run with the `--sandbox` flag.
Diffstat (limited to 'stack.yaml')
0 files changed, 0 insertions, 0 deletions
