Steve Kowalik 2022-09-02 05:07:50 +00:00 committed by Git OBS Bridge
parent a2b82842e5
commit 19674afc6d

View File

@ -1,8 +1,9 @@
-------------------------------------------------------------------
Thu Sep 1 03:48:37 UTC 2022 - Steve Kowalik <steven.kowalik@suse.com>
- http.server: Fix an open redirection vulnerability in the HTTP server
when an URI path starts with //. (bsc#1202624, CVE-2021-28861)
- Add patch CVE-2021-28861-double-slash-path.patch:
* http.server: Fix an open redirection vulnerability in the HTTP server
when an URI path starts with //. (bsc#1202624, CVE-2021-28861)
-------------------------------------------------------------------
Thu Jul 21 14:19:55 UTC 2022 - Matej Cepl <mcepl@suse.com>