[3.7] bpo-42967: only use '&' as a query string separator (GH-24297) (GH-24531)
bpo-42967: [security] Address a web cache-poisoning issue reported in urllib.parse.parse_qsl(). urllib.parse will only us "&" as query string separator by default instead of both ";" and "&" as allowed in earlier versions. An optional argument seperator with default value "&" is added to specify the separator. Co-authored-by:Éric Araujo <merwok@netwok.org> Co-authored-by:
Ken Jin <28750310+Fidget-Spinner@users.noreply.github.com> Co-authored-by:
Adam Goldschmidt <adamgold7@gmail.com> (cherry picked from commit fcbe0cb0)
Loading
Please register or sign in to comment