Change History (2)
comment:1 by , 2 years ago
Resolution: | → fixed |
---|---|
Status: | new → closed |
comment:2 by , 2 years ago
Priority: | normal → high |
---|
Retroactively promote to high for security issues:
Release notes are at https://docs.python.org/3/whatsnew/changelog.html
Two security related fixes:
- gh-87389: http.server: Fix an open redirection vulnerability in the HTTP server when an URI path starts with .
- gh-92888: Fix memoryview use after free when accessing the backing buffer in certain cases.
Note:
See TracTickets
for help on using tickets.
Fixed at commit 1b11115cd2bde70178f0b600de85f64a12cc36dc