Skip to content

4.10.17

Choose a tag to compare

@parseplatformorg parseplatformorg released this 15 Oct 00:26
· 6 commits to release-4.x.x since this release

4.10.17 (2022-10-15)

Bug Fixes

  • server crashes when receiving file download request with invalid byte range; this fixes a security vulnerability that allows an attacker to impact the availability of the server instance; the fix improves parsing of the range parameter to properly handle invalid range requests (GHSA-h423-w6qv-2wj3) (#8236) (3d7a61e)