Assets uploaded with appropriately crafted filenames may result in them being placed in a location different than what was configured.
assets fields.This has been fixed in 5.17.0.
{
"github_reviewed": true,
"nvd_published_at": "2024-11-19T17:15:56Z",
"github_reviewed_at": "2024-11-19T18:03:07Z",
"severity": "MODERATE",
"cwe_ids": [
"CWE-22"
]
}