ID: PMASA-2016-15 Date: 2016-05-25 Summary: File Traversal Protection Bypass on Error Reporting Description: A specially crafted payload could expose arbitrary files and their sizes via the error reporting component. The attacker must intercept and modify POST data to trigger a JavaScript error. Severity: Non-critical Mitigation factor: Set or upgrade to a more recent development commit. Affected Versions: Git 'master' development branch Unaffected Versions: All released versions Solution: Upgrade to a more recent snapshot or release version References: - Found thanks to Mozilla SOS program - CVE-2016-5098 - CWE-661 Patches: Commit on the 4.6 branch