Pylons / waitress

Waitress - A WSGI server for Python 3
https://docs.pylonsproject.org/projects/waitress/en/latest/
Other
1.44k stars 164 forks source link

Backport CVE-2022-24761 for tag v1.4.4 #387

Closed ravanelli closed 7 months ago

ravanelli commented 2 years ago

Hi Folks, We have a BZ to get the fix done in 2.1.1 https://github.com/Pylons/waitress/commit/9e0b8c801e4d505c2ffc91b891af4ba48af715e0 to the old versions available in EPEL

This backport was done for RHEL7 via CVE-2022-24761.

I created this FORK with an initial backport to v1.4.4. I wonder if we can create a new tag as v1.4.5 including this fix, + some help to validate it

ravanelli commented 2 years ago

cc @carlwgeorge