Ich habe gerade eine neue Version(v1.3.4) von CrowCpp veröffentlicht, sie enthält mehrere sicherheitsrelevante Bugfixes.
- GHSA-6mch-4jwv-f5q2 Global middleware rejection ignored during WebSocket upgrade, allowing authentication bypass
- GHSA-7×84-xhp8-6cqj json parsers parse depth limited to 1024 to prevent stack overflow
- GHSA-944c-h97m-jm2r WebSocket fragmented messages bypass the configured maximum payload limit
- GHSA-x6vq-298x-6qgq Trailing-slash redirects can emit protocol-relative Location headers
- GHSA-hc33-jfp4-5fqh Crow FileStore session cookie path traversal allows access to JSON files outside the session directory
Wie immer sind einige kleinere Verbesserungen im Release enthalten, die Release Notes enthalten die komplette Liste.

Kommentare