Skip to content

Commit

Permalink
Merge 0b753fb into d1e036b
Browse files Browse the repository at this point in the history
  • Loading branch information
dleskosky committed Oct 3, 2022
2 parents d1e036b + 0b753fb commit a3be3d1
Showing 1 changed file with 4 additions and 0 deletions.
4 changes: 4 additions & 0 deletions docs/security.md
Expand Up @@ -17,3 +17,7 @@ you may want to consider the following as you use TabPy:
- Execution of ad-hoc Python scripts can be disabled by turning off the
/evaluate endpoint. To disable /evaluate endpoint, set "TABPY_EVALUATE_ENABLE"
to false in config file.
- Always use the most up-to-date version of Python.
TabPy relies on Tornado and if older verions of Python are used with Tornado
then malicious users can potentially poison Python server web caches
with parameter cloaking.

0 comments on commit a3be3d1

Please sign in to comment.