1
0
mirror of https://github.com/django/django.git synced 2025-03-24 00:00:45 +00:00
Carl Meyer 41b4bc73ee [1.7.x] Stripped headers containing underscores to prevent spoofing in WSGI environ.
This is a security fix. Disclosure following shortly.

Thanks to Jedediah Smith for the report.
2015-01-13 13:02:56 -05:00
..