Skip to content
This repository has been archived by the owner on Feb 25, 2025. It is now read-only.

Sanitize Zimpl models #3

Open
rschwarz opened this issue Jun 16, 2016 · 0 comments
Open

Sanitize Zimpl models #3

rschwarz opened this issue Jun 16, 2016 · 0 comments

Comments

@rschwarz
Copy link
Owner

Zimpl supports reading files and printing their contents. And the scip subprocesses are started with the same user that started the zimplayground server. All files that are readible by this user can easily be leaked.

We could forbid reading from files, or check whether the path is located within some specific folder.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant