]> git.ipfire.org Git - thirdparty/tornado.git/commitdiff
Set version to 6.3.3
authorBen Darnell <ben@bendarnell.com>
Fri, 11 Aug 2023 02:38:19 +0000 (22:38 -0400)
committerBen Darnell <ben@bendarnell.com>
Fri, 11 Aug 2023 02:39:22 +0000 (22:39 -0400)
docs/releases.rst
docs/releases/v6.3.3.rst [new file with mode: 0644]
tornado/__init__.py

index fc7e41654f4d00790aa08c93019579921ff34315..076ac863314f0bdcff9faf97cec5a883016c0473 100644 (file)
@@ -4,6 +4,7 @@ Release notes
 .. toctree::
    :maxdepth: 2
 
+   releases/v6.3.3
    releases/v6.3.2
    releases/v6.3.1
    releases/v6.3.0
diff --git a/docs/releases/v6.3.3.rst b/docs/releases/v6.3.3.rst
new file mode 100644 (file)
index 0000000..7fe0110
--- /dev/null
@@ -0,0 +1,12 @@
+What's new in Tornado 6.3.3
+===========================
+
+Aug 11, 2023
+------------
+
+Security improvements
+~~~~~~~~~~~~~~~~~~~~~
+
+- The ``Content-Length`` header and ``chunked`` ``Transfer-Encoding`` sizes are now parsed
+  more strictly (according to the relevant RFCs) to avoid potential request-smuggling
+  vulnerabilities when deployed behind certain proxies.
index 475c1f612eeac18a2a7c7d1460e52c8c73cc7979..c2a8f25b43ff6964096679042f0b153df9c457b5 100644 (file)
@@ -22,8 +22,8 @@
 # is zero for an official release, positive for a development branch,
 # or negative for a release candidate or beta (after the base version
 # number has been incremented)
-version = "6.3.2"
-version_info = (6, 3, 2, 0)
+version = "6.3.3"
+version_info = (6, 3, 3, 0)
 
 import importlib
 import typing