You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
#3616 seems like a serious security flaw. Any content cached using the current page number as part of the cache key becomes vulnerable. Continuously hitting page numbers beyond the last page will quickly overwhelm the cache. At the very least there could be a sane max page number. Right now hitting https://--------.com/blog/p999999999999999999 returns uncached content (lots of queries) and generates a new cache (takes up disk space). An attacker could hit continuously incremented urls and quickly fill up the disk or take down a site.
The text was updated successfully, but these errors were encountered:
#3616 seems like a serious security flaw. Any content cached using the current page number as part of the cache key becomes vulnerable. Continuously hitting page numbers beyond the last page will quickly overwhelm the cache. At the very least there could be a sane max page number. Right now hitting https://--------.com/blog/p999999999999999999 returns uncached content (lots of queries) and generates a new cache (takes up disk space). An attacker could hit continuously incremented urls and quickly fill up the disk or take down a site.
The text was updated successfully, but these errors were encountered: