Files @ 38d1c99cd000
Branch filter:

Location: kallithea/docs/readme.rst

Søren Løvborg
login: enhance came_from validation

Drop urlparse and just validate that came_from is a RFC 3986 compliant path.

This blocks an HTTP header injection vulnerability discovered by
Gjoko Krstic <gjoko@zeroscience.mk> of Zero Science Lab (CVE-2015-5285)
1
2
3
.. _readme:

.. include:: ./../README.rst