Commit 049f8c1a authored by Mark J. Cox's avatar Mark J. Cox
Browse files

CAN-2004-1834 was created in March 2004 when it was reported

that mod_disk_cache would store these headers -- leading to a 
small potential risk that you'd end up with authentication headers
on disk and visible to users (or cgi scripts or whatever).  Make
a note which commit actually ended up closing this low impact issue.


git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@265719 13f79535-47bb-0310-9956-ffa450edef68
parent bfed16a6
Loading
Loading
Loading
Loading
+2 −1
Changes for CHANGES: 2 added lines, 1 removed line.
Original line number Diff line number Diff line
@@ -225,7 +225,8 @@ Changes with Apache 2.0.53
     is causing a potential problem with the LDAP shared memory cache.
     PR 31431 [Graham Leggett]
  *) mod_disk_cache: Do not store hop-by-hop headers.  [Justin Erenkrantz]
  *) SECURITY: CAN-2004-1834 (cve.mitre.org)
     mod_disk_cache: Do not store hop-by-hop headers.  [Justin Erenkrantz]
  *) Fix the re-linking issue when purging elements from the LDAP cache
     PR 24801.  [Jess Holle <jessh ptc.com>]