Commit 19a0ba6
Mark AuditLogEntry fields as readonly
Additionally this resolves a superuser-only security concern around being able to craft and inject pickled data into the AuditLogEntry.data field. This won't prevent malicious data in there through other means, but this is the only place it's exposed for raw input (beyond shell).
Thanks to Clément Berthaux from Synacktiv (www.synacktiv.com) for reporting this.1 parent 40e3cd8 commit 19a0ba6
1 file changed
+2
-0
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
312 | 312 | | |
313 | 313 | | |
314 | 314 | | |
| 315 | + | |
| 316 | + | |
315 | 317 | | |
316 | 318 | | |
317 | 319 | | |
| |||
0 commit comments