summaryrefslogtreecommitdiffstats
path: root/meta-python/recipes-devtools/python/python3-werkzeug/CVE-2023-25577.patch
diff options
context:
space:
mode:
authorXu Huan <xuhuan.fnst@fujitsu.com>2026-01-16 08:38:08 +0100
committerGyorgy Sarvari <skandigraun@gmail.com>2026-01-30 18:59:28 +0100
commitb7ab23179d01d442802721f2100e0409aa17e32a (patch)
treed34e47e3c7354c74b620cb6ad3b752fcecd1162a /meta-python/recipes-devtools/python/python3-werkzeug/CVE-2023-25577.patch
parent01098510f3988a91790eb0d79ac162dc4ca01206 (diff)
downloadmeta-openembedded-b7ab23179d01d442802721f2100e0409aa17e32a.tar.gz
python3-werkzeug: upgrade 2.1.1 -> 2.1.2
Changelog: ========== The development server does not set Transfer-Encoding: chunked for 1xx, 204, 304, and HEAD responses. Response HTML for exceptions and redirects starts with <!doctype html> and <html lang=en>. Fix ability to set some cache_control attributes to False. Disable keep-alive connections in the development server, which are not supported sufficiently by Python’s http.server. Signed-off-by: Xu Huan <xuhuan.fnst@fujitsu.com> Signed-off-by: Khem Raj <raj.khem@gmail.com> (cherry picked from commit 0704ebad0d31eec1737e0313b0f221085a9e8166) Rebased patches in Kirkstone. Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com>
Diffstat (limited to 'meta-python/recipes-devtools/python/python3-werkzeug/CVE-2023-25577.patch')
-rw-r--r--meta-python/recipes-devtools/python/python3-werkzeug/CVE-2023-25577.patch6
1 files changed, 3 insertions, 3 deletions
diff --git a/meta-python/recipes-devtools/python/python3-werkzeug/CVE-2023-25577.patch b/meta-python/recipes-devtools/python/python3-werkzeug/CVE-2023-25577.patch
index 61551d8fca..351f939b78 100644
--- a/meta-python/recipes-devtools/python/python3-werkzeug/CVE-2023-25577.patch
+++ b/meta-python/recipes-devtools/python/python3-werkzeug/CVE-2023-25577.patch
@@ -25,15 +25,15 @@ index a351d7c..6e809ba 100644
25+++ b/CHANGES.rst 25+++ b/CHANGES.rst
26@@ -1,5 +1,10 @@ 26@@ -1,5 +1,10 @@
27 .. currentmodule:: werkzeug 27 .. currentmodule:: werkzeug
28 28
29+- Specify a maximum number of multipart parts, default 1000, after which a 29+- Specify a maximum number of multipart parts, default 1000, after which a
30+ ``RequestEntityTooLarge`` exception is raised on parsing. This mitigates a DoS 30+ ``RequestEntityTooLarge`` exception is raised on parsing. This mitigates a DoS
31+ attack where a larger number of form/file parts would result in disproportionate 31+ attack where a larger number of form/file parts would result in disproportionate
32+ resource use. 32+ resource use.
33+ 33+
34 Version 2.1.1 34 Version 2.1.2
35 ------------- 35 -------------
36 36
37diff --git a/docs/request_data.rst b/docs/request_data.rst 37diff --git a/docs/request_data.rst b/docs/request_data.rst
38index 83c6278..e55841e 100644 38index 83c6278..e55841e 100644
39--- a/docs/request_data.rst 39--- a/docs/request_data.rst