#31604: Should SafeExceptionReporterFilter cleanse setting keys whose name
matches
"URL" in part, too?
-----------------------------------+--------------------------------------
Reporter: Sebastian Pipping | Owner: (none)
Type: Uncategorized | Status: new
Component: Error reporting | Version: dev
Severity: Normal | Resolution:
Keywords: security debug | Triage Stage: Unreviewed
Has patch: 1 | Needs documentation: 0
Needs tests: 0 | Patch needs improvement: 0
Easy pickings: 0 | UI/UX: 0
-----------------------------------+--------------------------------------
Changes (by Sebastian Pipping):
* cc: Sebastian Pipping (added)
* has_patch: 0 => 1
* keywords: => security debug
* resolution: wontfix =>
* status: closed => new
Comment:
Re-opening because it took part in allowing potential arbitrary remote
code execution as explained at
https://github.com/climateconnect/climateconnect/pull/1331#issuecomment-2397881433
in practice … Pull request upcoming…
--
Ticket URL: <https://code.djangoproject.com/ticket/31604#comment:2>
Django <https://code.djangoproject.com/>
The Web framework for perfectionists with deadlines.
--
You received this message because you are subscribed to the Google Groups
"Django updates" group.
To unsubscribe from this group and stop receiving emails from it, send an email
to [email protected].
To view this discussion visit
https://groups.google.com/d/msgid/django-updates/0107019311f1c0ba-d60ea326-678a-4d5f-a3aa-1fdaaebedaac-000000%40eu-central-1.amazonses.com.