1
0
mirror of https://github.com/django/django.git synced 2025-04-01 12:06:43 +00:00
Carl Meyer d7597b31d5 [1.6.x] Stripped headers containing underscores to prevent spoofing in WSGI environ.
This is a security fix. Disclosure following shortly.

Thanks to Jedediah Smith for the report.
2015-01-13 13:10:11 -05:00
..