diff options
| author | ianb <devnull@localhost> | 2006-12-18 00:28:21 +0000 |
|---|---|---|
| committer | ianb <devnull@localhost> | 2006-12-18 00:28:21 +0000 |
| commit | 7c0b1546341ae5761701c4d667cbb6e87327ba19 (patch) | |
| tree | ed070f240b8a249e2e407eecb1993ed558a58682 /docs | |
| parent | 165668aae8890fba08a5b40a83a814e4c74bf659 (diff) | |
| download | paste-7c0b1546341ae5761701c4d667cbb6e87327ba19.tar.gz | |
Security fix for StaticURLParser, plus unquote SCRIPT_NAME and PATH_INFO, plus don't double-unquote in StaticURLParser
Diffstat (limited to 'docs')
| -rw-r--r-- | docs/news.txt | 10 |
1 files changed, 10 insertions, 0 deletions
diff --git a/docs/news.txt b/docs/news.txt index 71e925e..6517f0c 100644 --- a/docs/news.txt +++ b/docs/news.txt @@ -6,6 +6,16 @@ News svn trunk --------- +* Security fix for ``paste.urlparser.StaticURLParser``. The problem + allowed escaping the root (and reading files) when used with + ``paste.httpserver`` (this does not effect other servers, and does + not apply when proxying requests from Apache to + ``paste.httpserver``). + +* ``paste.httpserver`` and ``paste.fixture.TestApp`` url-unquote + ``SCRIPT_NAME`` and ``PATH_INFO``, as specified in the CGI spec. + Thanks to Jon Nelson for pointing out both these issues. + * ``paste.registry`` now works within the ``EvalException`` interactive debugger. |
