-
Notifications
You must be signed in to change notification settings - Fork 665
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
[SECURITY] Prevent information disclosure in tests bootstrap
Both, the UnitTestsBootstrap and FunctionalTestsBootstrap set display_errors to 1 which shows errors and warnings by default. If you call those scripts within web context the files can't be loaded and the error message shows the website root path. The patch adds proper checks before files are loaded and exits if an error occurs. Resolves: #67900 Releases: 6.2 Security-Bulletin: TYPO3-CORE-SA-2015-008 Change-Id: I1e294bcd2f6cd7c2a32f54a890ca2d4a869c9fda Reviewed-on: http://review.typo3.org/43120 Reviewed-by: Oliver Hader <oliver.hader@typo3.org> Tested-by: Oliver Hader <oliver.hader@typo3.org>
- Loading branch information
1 parent
045b4ea
commit ed1e46f
Showing
2 changed files
with
16 additions
and
1 deletion.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters