fix(preview): check mime type before processing with Imagick#44710
fix(preview): check mime type before processing with Imagick#44710nickvergessen merged 1 commit intomasterfrom
Conversation
fb5711d to
ffe31a5
Compare
ffe31a5 to
0e612ae
Compare
|
I made one change: the default behavior of the |
c46ecd6 to
31fc099
Compare
31fc099 to
5d4d84b
Compare
Signed-off-by: Varun Patil <varunpatil@ucla.edu>
5d4d84b to
4ab40e3
Compare
|
Bump |
|
Bump (2) |
|
yeah, there was a freeze recently for updates, so this could not proceed with all necessary energy |
|
/backport to stable29 |
|
/backport to stable28 |
|
/backport to stable27 |
|
Hi @nickvergessen, Recently I'm starting to use the HEIC format and saw the image previews are not working by default. I did some searching and found a nasty CVE from 2021 https://hackerone.com/reports/1261413 which was fixed by disabling the HEIC preview in #28077. With this change and checking the mime type it does seem safe to me to enable HEIC, but I do notice the default is still to keep it disabled. Could you confirm whether it is considered secure to enable HEIC previews in the latest Nextcloud versions? I would love to have previews but of course not at the cost of a potentially critical security issue. Many thanks! |
I'm not too much into previews and Imagick/HEIC things, sorry. |
No description provided.