##// END OF EJS Templates
security: limit the maximum password lenght to 72 characters to prevent possible...
security: limit the maximum password lenght to 72 characters to prevent possible server side resource consumption attack. - bcrypt heavy computation can lead to DOS using a very long password .eg 10**8 lenght. - we allowed this on registration or on password update

File last commit:

r1167:c0cc2e45 default
r2192:a51e727d stable
Show More
release-notes-4.3.1.rst
35 lines | 468 B | text/x-rst | RstLexer

|RCE| 4.3.1 |RNS|

Release Date

  • 2016-08-23

New Features

General

Security

Performance

Fixes

  • Core: fixed database session cleanups. This will make sure RhodeCode can function correctly after database server problems. Fixes #4173, refs #4166
  • Diffs: limit the file context to ~1mln lines. Fixes #4184, also make sure this doesn't trigger Integer overflow for msgpack.