Skip to content
Snippets Groups Projects
  1. Apr 09, 2021
  2. Mar 15, 2021
  3. Mar 07, 2021
  4. Mar 03, 2021
  5. Mar 02, 2021
  6. Feb 26, 2021
  7. Feb 22, 2021
  8. Feb 19, 2021
  9. Feb 17, 2021
  10. Feb 15, 2021
  11. Feb 09, 2021
  12. Feb 08, 2021
  13. Feb 06, 2021
  14. Feb 05, 2021
  15. Jan 17, 2021
  16. Jan 15, 2021
  17. Sep 22, 2020
  18. Sep 17, 2020
  19. Sep 14, 2020
    • Andrew Dolgov's avatar
      - fix multiple vulnerabilities in af_proxy_http · c3d14e1f
      Andrew Dolgov authored
      - fix vulnerability in rewrite_relative_url() which prevented some URLs from being properly absolutized
      - fetch_file_contents: validate all URLs before requesting them
      - validate URLs: explicitly whitelist http and https scheme, forbid everything else
      - DiskCache/cached_url: only serve whitelisted content types (images, video)
      - simplify filename/URL handling code, remove and consolidate some less-used functions
      c3d14e1f
  20. Aug 13, 2020
  21. Apr 29, 2020
  22. Mar 10, 2020
  23. Nov 27, 2019
  24. Oct 07, 2019
Loading