We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
There was an error while loading. Please reload this page.
1 parent df784b9 commit 192d03fCopy full SHA for 192d03f
CHANGES.txt
@@ -1,6 +1,19 @@
1
Unreleased
2
----------
3
4
+Security Fix
5
+~~~~~~~~~~~~
6
+
7
+- The use of WebOb's Response object to redirect a request to a new location
8
+ can lead to an open redirect if the Location header is not a full URI.
9
10
+ See https://github.com/Pylons/webob/security/advisories/GHSA-mg3v-6m49-jhp3
11
+ and CVE-2024-42353
12
13
+ Thanks to Sara Gao for the report
14
15
+ (This fix was released in WebOb 1.8.8)
16
17
Feature
18
~~~~~~~
19
0 commit comments