Security Advisories (1)
CPANSA-Jifty-2011-01 (2011-03-17)

The path as passed in the fragment request data structure was used verbatim in the dispatcher and other locations. This possibly allowed requests to walk around ACLs by requesting '/some/safe/place/../../../dangerous' as a fragment.

NAME

Jifty::Upgrade::Internal - Upgrades to Jifty-specific schemas and data

UPGRADES

Version 0.60427

Version metadata, previously stored in _db_version, get migrated to _jifty_metadata, so it could be used to store more than one row usefully.