summaryrefslogtreecommitdiffstats
path: root/meta-python/recipes-devtools/python/python3-waitress_1.4.3.bb
Commit message (Collapse)AuthorAgeFilesLines
* python3-waitress: upgrade 1.4.2 -> 1.4.3Pierre-Jean Texier2020-04-121-0/+12
This is a security release: - In Waitress version 1.4.2 a new regular expression was added to validate the headers that Waitress receives to make sure that it matches RFC7230. Unfortunately the regular expression was written in a way that with invalid input it leads to catastrophic backtracking which allows for a Denial of Service and CPU usage going to a 100%. Signed-off-by: Pierre-Jean Texier <pjtexier@koncepto.io> Signed-off-by: Khem Raj <raj.khem@gmail.com>