mirror of
https://github.com/silverstripe/silverstripe-installer
synced 2024-10-22 17:05:33 +02:00
Prevent YAML access in IIS by default (fixes #8233)
Since SS3 keeps values in configuration, direct access to known paths might expose them
This commit is contained in:
parent
494bfc7863
commit
98135df7d3
@ -10,6 +10,7 @@
|
|||||||
</hiddenSegments>
|
</hiddenSegments>
|
||||||
<fileExtensions allowUnlisted="true" >
|
<fileExtensions allowUnlisted="true" >
|
||||||
<add fileExtension=".ss" allowed="false"/>
|
<add fileExtension=".ss" allowed="false"/>
|
||||||
|
<add fileExtension=".yml" allowed="false"/>
|
||||||
</fileExtensions>
|
</fileExtensions>
|
||||||
</requestFiltering>
|
</requestFiltering>
|
||||||
</security>
|
</security>
|
||||||
|
Loading…
Reference in New Issue
Block a user