Skip to content

Fix lack of URL normalization

Compare
Choose a tag to compare
@guimard guimard released this 09 Sep 09:16
· 153 commits to master since this release

This release fixes CVE-2020-24660. Before this release, when access rules are used inside a protected host, some URL encodings may bypass filtering system (see also security advisory).