FazBrowse GitHub Viewer | Trending |
URL:
| Home
Tools: [Download Repo ZIP]   [Original HTTPS Page]

[3.9] bpo-43882 - urllib.parse should sanitize urls containing ASCII newline and tabs. (GH-25595) by miss-islington · Pull Request #25725 · python/cpython · GitHub

/ cpython Public

[3.9] bpo-43882 - urllib.parse should sanitize urls containing ASCII newline and tabs. (GH-25595) - #25725

Merged
orsenthil merged 2 commits into
python:3.9from
miss-islington:backport-76cd81d-3.9
Apr 29, 2021
Merged

[3.9] bpo-43882 - urllib.parse should sanitize urls containing ASCII newline and tabs. (GH-25595)#25725
orsenthil merged 2 commits into
python:3.9from
miss-islington:backport-76cd81d-3.9

Conversation

miss-islington commented Apr 29, 2021
edited by bedevere-bot
Loading

Copy link
Copy Markdown
Contributor
  • issue43882 - urllib.parse should sanitize urls containing ASCII newline and tabs.

Co-authored-by: Gregory P. Smith greg@krypto.org
Co-authored-by: Serhiy Storchaka storchaka@gmail.com
(cherry picked from commit 76cd81d)

Co-authored-by: Senthil Kumaran senthil@uthcode.com

https://bugs.python.org/issue43882

…e and tabs. (pythonGH-25595)

* issue43882 - urllib.parse should sanitize urls containing ASCII newline and tabs.

Co-authored-by: Gregory P. Smith <greg@krypto.org>
Co-authored-by: Serhiy Storchaka <storchaka@gmail.com>
(cherry picked from commit 76cd81d)

Co-authored-by: Senthil Kumaran <senthil@uthcode.com>

Copy link
Copy Markdown
Contributor Author

@orsenthil: Status check is done, and it's a success ✅ .

Copy link
Copy Markdown
Contributor Author

@orsenthil: Status check is done, and it's a success ✅ .

bedevere-bot added type-bug An unexpected behavior, bug, or error type-security A security issue labels Apr 29, 2021

Copy link
Copy Markdown
Contributor Author

@orsenthil: Status check is done, and it's a failure ❌ .

orsenthil merged commit 491fde0 into python:3.9 Apr 29, 2021
miss-islington deleted the backport-76cd81d-3.9 branch April 29, 2021 17:57
mlissner added a commit to freelawproject/courtlistener that referenced this pull request Apr 30, 2021
This goes to show that messing with security-critical code is a nasty
business and often a mistake. Luckily, we have tests, but what
happened here is that I tweaked the code to separate out checks from
redirection. In so doing, I removed pulled the quoting code into the
checks, but took it out of the redirection part. So previously, we'd
quote a URL before redirecting it, now we didn't.

To fix this, I copied the fix from Python's standard lib that you can
see here:

    python/cpython#25725

Instead of quoting it, we just make sure it doesn't have newlines. If
it does, we bail.
gentoo-bot pushed a commit to gentoo/cpython that referenced this pull request May 2, 2021
…newline and tabs. (pythonGH-25595) (pythonGH-25725)

* bpo-43882 - urllib.parse should sanitize urls containing ASCII newline and tabs. (pythonGH-25595)

Co-authored-by: Gregory P. Smith <greg@krypto.org>
Co-authored-by: Serhiy Storchaka <storchaka@gmail.com>
(cherry picked from commit 76cd81d)
Co-authored-by: Senthil Kumaran <skumaran@gatech.edu>
(backported to Python 2.7 by Michał Górny)
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode characters
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

type-bug An unexpected behavior, bug, or error type-security A security issue

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants


Back | FazBrowse Home | New Git URL