Security Advisories (1)
CPANSA-Jifty-2011-01 (2011-03-17)

The path as passed in the fragment request data structure was used verbatim in the dispatcher and other locations. This possibly allowed requests to walk around ACLs by requesting '/some/safe/place/../../../dangerous' as a fragment.

NAME

Jifty::Server::Fork::NetServer - Sets up children for Jifty::Server::Fork

METHODS

post_accept_hook

After forking every connection, resetup the database connections so we don't share them with our parent.

log

Log messages should use Jifty's Log::Log4perl infrastructure, not STDERR.