summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorPedro Alvarez <palvarez89@gmail.com>2018-08-15 13:04:27 +0100
committerPedro Alvarez <palvarez89@gmail.com>2018-08-15 13:04:30 +0100
commite709c89e63a1c9156bf78258a0363ff86d1893c4 (patch)
treeb04fa6d4ec72ad093c2c0cad7fa1110d140294f0
parent1f2edd45b03a3e9d86d7c77847612c969b60b86f (diff)
downloadtrove-setup-e709c89e63a1c9156bf78258a0363ff86d1893c4.tar.gz
Set enable-http-clone=0 to avoid Cgit vulerabilityHEADmaster
More information at https://nvd.nist.gov/vuln/detail/CVE-2018-14912
-rw-r--r--share/etc/cgitrc2
1 files changed, 2 insertions, 0 deletions
diff --git a/share/etc/cgitrc b/share/etc/cgitrc
index 36e37f4..1071e9a 100644
--- a/share/etc/cgitrc
+++ b/share/etc/cgitrc
@@ -15,6 +15,8 @@ enable-commit-graph=1
enable-log-filecount=1
enable-log-linecount=1
+enable-http-clone=0
+
mimetype.gif=image/gif
mimetype.html=text/html
mimetype.jpg=image/jpeg