Product Enhancements
Mitigated PAL Temp File Vulnerability
ID# 62271, 62493
To eliminate a potential security vulnerability, weāve discontinued use of the PAL āUploadsā folder, previously used to temporarily store files uploaded to the Public Access Link before being saved to the PAL database. These files are now stored outside the PAL installation location, ensuring that these temp files cannot be accessed via the internet or HTTP protocol. Once these files are saved to the PAL database, they are immediately deleted from the temporary location.
Bug Fix
Weāve addressed the following bug in the FOIAXpress PAL 11.5.1 release:
ID | Description |
|---|---|
62274 | Resolved a PAL issue where files uploaded to PAL were not consistently deleted from the temporary folder after being added to the PAL database. All temp files are now deleted immediately after being added to the database. |