Mercurial > hg > nginx-quic
comparison conf/uwsgi_params @ 6243:4821fc788c12
Cache: check the whole cache key in addition to hashes.
This prevents a potential attack that discloses cached data if an attacker
will be able to craft a hash collision between some cache key the attacker
is allowed to access and another cache key with protected data.
See http://mailman.nginx.org/pipermail/nginx-devel/2015-September/007288.html.
Thanks to Gena Makhomed and Sergey Brester.
author | Maxim Dounin <mdounin@mdounin.ru> |
---|---|
date | Fri, 11 Sep 2015 17:03:56 +0300 |
parents | 62869a9b2e7d |
children |
comparison
equal
deleted
inserted
replaced
6242:0e3a45ec2a3a | 6243:4821fc788c12 |
---|