@@ -1,3 +1,7 @@
+03-JUN-2018: 8.7.4
+
+- Fixes possible SSRF in proxy servlet
02-JUN-2018: 8.7.3
- Fixes overridden layout menu
@@ -1 +1 @@
-8.7.3
+8.7.4
@@ -63,7 +63,7 @@ public class ProxyServlet extends HttpServlet
dom = "";
}
- if (dom != null && urlParam != null)
+ if (dom != null && urlParam != null && (urlParam.startsWith("http://") || urlParam.startsWith("https://")))
{
request.setCharacterEncoding("UTF-8");
response.setCharacterEncoding("UTF-8");
@@ -1,7 +1,7 @@
CACHE MANIFEST
# THIS FILE WAS GENERATED. DO NOT MODIFY!
-# 06/02/2018 02:05 PM
+# 06/03/2018 08:54 AM
app.html
index.html?offline=1