summaryrefslogtreecommitdiff
path: root/docs
diff options
context:
space:
mode:
authorianb <devnull@localhost>2006-12-18 00:28:21 +0000
committerianb <devnull@localhost>2006-12-18 00:28:21 +0000
commit7c0b1546341ae5761701c4d667cbb6e87327ba19 (patch)
treeed070f240b8a249e2e407eecb1993ed558a58682 /docs
parent165668aae8890fba08a5b40a83a814e4c74bf659 (diff)
downloadpaste-7c0b1546341ae5761701c4d667cbb6e87327ba19.tar.gz
Security fix for StaticURLParser, plus unquote SCRIPT_NAME and PATH_INFO, plus don't double-unquote in StaticURLParser
Diffstat (limited to 'docs')
-rw-r--r--docs/news.txt10
1 files changed, 10 insertions, 0 deletions
diff --git a/docs/news.txt b/docs/news.txt
index 71e925e..6517f0c 100644
--- a/docs/news.txt
+++ b/docs/news.txt
@@ -6,6 +6,16 @@ News
svn trunk
---------
+* Security fix for ``paste.urlparser.StaticURLParser``. The problem
+ allowed escaping the root (and reading files) when used with
+ ``paste.httpserver`` (this does not effect other servers, and does
+ not apply when proxying requests from Apache to
+ ``paste.httpserver``).
+
+* ``paste.httpserver`` and ``paste.fixture.TestApp`` url-unquote
+ ``SCRIPT_NAME`` and ``PATH_INFO``, as specified in the CGI spec.
+ Thanks to Jon Nelson for pointing out both these issues.
+
* ``paste.registry`` now works within the ``EvalException``
interactive debugger.