Skip to content
This repository has been archived by the owner on Jan 16, 2021. It is now read-only.

If a header contains a newline, don't output it #38

Merged
merged 1 commit into from
May 28, 2014

Conversation

s4y
Copy link

@s4y s4y commented May 1, 2014

Fixes a vulnerability where an attacker uses the value of a header (e.g. the target of a redirect) to insert their own headers.

Fixes a vulnerability where an attacker uses the value of a header (e.g.
the target of a redirect) to insert their own headers.
mmaxim added a commit that referenced this pull request May 28, 2014
If a header contains a newline, don't output it
@mmaxim mmaxim merged commit 7ad85cc into OkCupid:master May 28, 2014
@s4y s4y deleted the patch-drop-newline-headers branch February 17, 2015 23:15
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants