diff options
| author | Senthil Kumaran <senthil@uthcode.com> | 2021-02-15 18:34:14 (GMT) |
|---|---|---|
| committer | GitHub <noreply@github.com> | 2021-02-15 18:34:14 (GMT) |
| commit | d0d4d30882fe3ab9b1badbecf5d15d94326fd13e (patch) | |
| tree | 5f9cf7c531d89da3dab9d3315bde1142a5cde9bc /Python/pythonrun.c | |
| parent | d9b8f138b7df3b455b54653ca59f491b4840d6fa (diff) | |
| download | cpython-d0d4d30882fe3ab9b1badbecf5d15d94326fd13e.zip cpython-d0d4d30882fe3ab9b1badbecf5d15d94326fd13e.tar.gz cpython-d0d4d30882fe3ab9b1badbecf5d15d94326fd13e.tar.bz2 | |
[3.7] bpo-42967: only use '&' as a query string separator (GH-24297) (GH-24531)
bpo-42967: [security] Address a web cache-poisoning issue reported in
urllib.parse.parse_qsl().
urllib.parse will only us "&" as query string separator by default
instead of both ";" and "&" as allowed in earlier versions. An optional
argument seperator with default value "&" is added to specify the
separator.
Co-authored-by: Éric Araujo <merwok@netwok.org>
Co-authored-by: Ken Jin <28750310+Fidget-Spinner@users.noreply.github.com>
Co-authored-by: Adam Goldschmidt <adamgold7@gmail.com>
(cherry picked from commit fcbe0cb04d35189401c0c880ebfb4311e952d776)
Diffstat (limited to 'Python/pythonrun.c')
0 files changed, 0 insertions, 0 deletions
