I can't browse the tree in bonsai. The first two levels are OK, but the third level seems to fall back to the first.
Steps to reproduce please? What did you click on in what order?
To reproduce, click on the URL provided above. Expected output: A list of directories that are inside mozilla/xpfe, e.g., AppCores/ apprunner/ components/ tools/ CVS/ appshell/ global/ widgets/ Makefile bootstrap/ macbuild/ xpviewer/ Makefile.in browser/ main/ appfilelocprovider/ communicator/ test/ Actual result: A list of directories that are in cvsroot.
Confirmed. Actually affects all third-level directories in all branches that are listed. This is major enough I'm sure someone would have noticed already if it had been around a while. What changed on bonsai recently?
Tara fixed a security hole last week with directory traversal. I can't find a bug for it though.
Created attachment 130324 [details] [diff] [review] Patch someone forgot to escape the dots in the regexp. Guess what a dot does in a regexp? :)
This has already been applied manually on bonsai.mozilla.org because I had a desperate need to use it tonight. :)
Attachment #130324 - Flags: review?(tara)
yeah, there was never a bug that I filed on that security issue, I just sent an e-mail to email@example.com and firstname.lastname@example.org. Since the issue is fixed, the problem was that ../ could be used to move higher than the CVS root which shouldn't be allowed. There is still an issue with ./.. as the directory. I don't think the fix was ever checked into the bonsai for gila either.
OS: MacOS X → All
Status: NEW → RESOLVED
Last Resolved: 15 years ago
Resolution: --- → FIXED
You need to log in before you can comment on or make changes to this bug.