Nginx 1.21.1 sii deynta

Qeybta ugu weyn ee nginx 1.21.1 ayaa la sii daayay, taas oo horumarinta sifooyinka cusub ay sii socoto (marka la barbar dhigo laanta xasilloon ee 1.20, kaliya isbeddellada la xidhiidha ciribtirka khaladaadka halista ah iyo dayacanka ayaa la sameeyay).

Isbeddellada ugu waaweyn:

  • Nginx hadda had iyo jeer waxay soo celisaa qalad marka la isticmaalayo habka ku xidhidh; marka si isku mid ah loo qeexo "Content-Length" iyo "Tranfer-Encoding" madaxyada; marka ay jiraan meelo bannaan ama xarfo koontaroolaya xargaha weydiinta, magaca cinwaanka HTTP, ama qiimaha madaxa Host.
  • Tijaabada qaabeynta oo la hagaajiyay marka la isticmaalayo meelo badan oo dhegeysi ah.
  • Baxsashada jilayaasha """, "<", ">", "\", "^", "`", "{", "|" waa la hagaajiyay. iyo "}" markaad wakiil ka tahay isbeddelka URI.
  • Isticmaalka xusuusta oo la dhimay ee codsiyada socodsiinta dheer marka wakiil la isticmaalayo in ka badan 64 kaydiyayaal.

Source: opennet.ru

Add a comment