]> git.ipfire.org Git - thirdparty/apache/httpd.git/commit
flags.xml: Add examples and security warnings for UnsafeAllow3F and UnsafePrefixStat
authorRich Bowen <rbowen@apache.org>
Fri, 15 May 2026 20:03:35 +0000 (20:03 +0000)
committerRich Bowen <rbowen@apache.org>
Fri, 15 May 2026 20:03:35 +0000 (20:03 +0000)
commita1f226f0372b3be663ec39c2bad25b013512cab2
tree0c18768e30b9fb30f1da440e0ff6fc0b3d4ca9bd
parent86fc017e2aa35d02182b310b07f9b92ca476b104
flags.xml: Add examples and security warnings for UnsafeAllow3F and UnsafePrefixStat

Both flags were introduced to address CVE-2024-38474 and CVE-2024-38475
respectively. Add practical examples showing common scenarios where each
flag is needed (PHP front controller for UnsafeAllow3F; backreference-
starting substitution for UnsafePrefixStat), along with warning notes
linking to the relevant CVEs and advising restraint in their use.

git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/trunk@1934248 13f79535-47bb-0310-9956-ffa450edef68
docs/manual/rewrite/flags.xml