summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorAaron Patterson <tenderlove@ruby-lang.org>2023-03-02 14:44:22 -0800
committerAaron Patterson <tenderlove@ruby-lang.org>2023-03-02 14:53:13 -0800
commit7bdc55dd21ec76811ad74c1ae14c1588d2f2ca49 (patch)
treef5c08ae730422da43811156e9905e23a6cdec17b
parentb632718265fa5ffa547b060331341a1e216b4ffa (diff)
downloadrack-2-1-stable.tar.gz
bump versionv2.1.4.32-1-stable
-rw-r--r--CHANGELOG.md4
-rw-r--r--lib/rack.rb2
2 files changed, 5 insertions, 1 deletions
diff --git a/CHANGELOG.md b/CHANGELOG.md
index 25e9dd3e..b3f52b04 100644
--- a/CHANGELOG.md
+++ b/CHANGELOG.md
@@ -1,3 +1,7 @@
+## [2.1.4.3] - 2023-03-02
+
+- [CVE-2023-27530] Introduce multipart_total_part_limit to limit total parts
+
## [2.1.4.2] - 2022-01-17
- [CVE-2022-44571] Fix ReDoS vulnerability in multipart parser
diff --git a/lib/rack.rb b/lib/rack.rb
index 76cb4cba..e34b435b 100644
--- a/lib/rack.rb
+++ b/lib/rack.rb
@@ -20,7 +20,7 @@ module Rack
VERSION.join(".")
end
- RELEASE = "2.1.4.2"
+ RELEASE = "2.1.4.3"
# Return the Rack release as a dotted string.
def self.release