-
-
Notifications
You must be signed in to change notification settings - Fork 4.7k
fix(preview): check mime type before processing with Imagick #44710
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
fb5711d to
ffe31a5
Compare
ffe31a5 to
0e612ae
Compare
|
I made one change: the default behavior of the |
c46ecd6 to
31fc099
Compare
31fc099 to
5d4d84b
Compare
Signed-off-by: Varun Patil <[email protected]>
5d4d84b to
4ab40e3
Compare
|
Bump |
|
Bump (2) |
|
yeah, there was a freeze recently for updates, so this could not proceed with all necessary energy |
|
/backport to stable29 |
|
/backport to stable28 |
|
/backport to stable27 |
|
Hi @nickvergessen, Recently I'm starting to use the HEIC format and saw the image previews are not working by default. I did some searching and found a nasty CVE from 2021 https://hackerone.com/reports/1261413 which was fixed by disabling the HEIC preview in #28077. With this change and checking the mime type it does seem safe to me to enable HEIC, but I do notice the default is still to keep it disabled. Could you confirm whether it is considered secure to enable HEIC previews in the latest Nextcloud versions? I would love to have previews but of course not at the cost of a potentially critical security issue. Many thanks! |
I'm not too much into previews and Imagick/HEIC things, sorry. |
No description provided.