Details
Description
Lion Tree <liontree0110@gmail.com> has reported us that "CVE-2020-1938 is not fully fixed".
Though it was fixed by OFBIZ-11407, it still possible for an authenticated user to upload a webshell included in an image using one of the OFBiz upload possibilities. That of course is not new and already covered by OFBIZ-12080 "Secure the uploads", but was still incomplete.
So this Jira covers 2 points:
- Disable bypass of Tomcat due to setting in framework/catalina/ofbiz-component.xml
- Enforce upload prevention of webshells, specifically but not only those included in images