aboutsummaryrefslogtreecommitdiffstats
path: root/lib/ssl/src/ssl_connection.erl
diff options
context:
space:
mode:
authorHamidreza Soleimani <[email protected]>2017-10-29 14:33:02 +0100
committerHamidreza Soleimani <[email protected]>2017-10-29 21:26:42 +0100
commit70a813c20a829ed47feb6a4b2e7b0332adac6c4f (patch)
tree1fc201d333059188ad7040707f6d098e2e7c73ae /lib/ssl/src/ssl_connection.erl
parentf3d069dd1e3978b240c0f99c5609735e72ea8e8c (diff)
downloadotp-70a813c20a829ed47feb6a4b2e7b0332adac6c4f.tar.gz
otp-70a813c20a829ed47feb6a4b2e7b0332adac6c4f.tar.bz2
otp-70a813c20a829ed47feb6a4b2e7b0332adac6c4f.zip
[#ERL-407]: Fix httpc misbehaviour based on RFC7230, section 3.3.3
If a message is received with both a Transfer-Encoding and a Content-Length header field, it might indicate an attempt to perform request smuggling or response splitting and must be handled as an error in default mode (not relaxed mode). Bug report: https://bugs.erlang.org/browse/ERL-407
Diffstat (limited to 'lib/ssl/src/ssl_connection.erl')
0 files changed, 0 insertions, 0 deletions