Skip to content

Commit

Permalink
4.3.2 and 3.12.3 release notes
Browse files Browse the repository at this point in the history
  • Loading branch information
nateberkopec committed Feb 27, 2020
1 parent 1b17e85 commit 37928cb
Showing 1 changed file with 5 additions and 0 deletions.
5 changes: 5 additions & 0 deletions History.md
Expand Up @@ -4,6 +4,11 @@

* x bugfixes

## 4.3.2 and 3.12.3 / 2020-02-27

* Security
* Fix: Prevent HTTP Response splitting via CR/LF in header values. CVE-2020-5247.

This comment has been minimized.

Copy link
@gingerlime

gingerlime Feb 28, 2020

Contributor

Is this the right CVE? https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-5247 (sorry, I'm not that familiar with how these get assigned), but I was trying to look for info about the vulnerability, to assess its criticality, i.e. how fast we should get this fix out.

This comment has been minimized.

Copy link
@gingerlime

gingerlime Feb 28, 2020

Contributor

sorry, found GHSA-84j7-475p-hp8v

This comment has been minimized.

Copy link
@nateberkopec

nateberkopec Feb 28, 2020

Author Member

Thanks. I didn't know that those take a while to propagate. In the future I'll include the GHSA too, which goes up instantly.


## 4.3.1 and 3.12.2 / 2019-12-05

* Security
Expand Down

0 comments on commit 37928cb

Please sign in to comment.