angler-fishThe Vulnerability History Project

[1.9.x] Fixed CVE-2016-7401 -- Fixed CSRF protection bypass on a site with Google Analytics.

      This is a security fix.

Backport of "refs #26158 -- rewrote http.parse_cookie() to better match
browsers." 93a135d111c2569d88d65a3f4ad9e6d9ad291452 from master
    
commit d1bc980db1c0fffd6d60677e62f70beadb9fe64a
+13 -16
-18
-18
-2
+1 -51
+4
expand_less