)]}'
{
  "commit": "01b99447729a3d43891997806106be6bec3637ff",
  "tree": "3f8adf38e27b95bf79c9fa30519bff704a481397",
  "parents": [
    "7fd6a8c4507c469a3a2f94004cf2ff7174bab568"
  ],
  "author": {
    "name": "William A. Rowe Jr",
    "email": "wrowe@apache.org",
    "time": "Wed Oct 02 21:35:57 2002 +0000"
  },
  "committer": {
    "name": "William A. Rowe Jr",
    "email": "wrowe@apache.org",
    "time": "Wed Oct 02 21:35:57 2002 +0000"
  },
  "message": "  *) SECURITY: [CAN-2002-0840] HTML-escape the address produced by\n     ap_server_signature() against this cross-site scripting\n     vulnerability exposed by the directive \u0027UseCanonicalName Off\u0027.\n     Also HTML-escape the SERVER_NAME environment variable for CGI\n     and SSI requests.  It\u0027s safe to escape as only the \u0027\u003c\u0027, \u0027\u003e\u0027,\n     and \u0027\u0026\u0027 characters are affected, which won\u0027t appear in a valid\n     hostname.  Reported by Matthew Murphy \u003cmattmurphy@kc.rr.com\u003e.\n     [Brian Pane]\n\n\ngit-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/trunk@97064 13f79535-47bb-0310-9956-ffa450edef68\n",
  "tree_diff": [
    {
      "type": "modify",
      "old_id": "83b39ca091e9cfd382544f5f1571d4020b1404dc",
      "old_mode": 33188,
      "old_path": "CHANGES",
      "new_id": "5577012a1cc0fe6d293deac71aba8a31cda84c1a",
      "new_mode": 33188,
      "new_path": "CHANGES"
    },
    {
      "type": "modify",
      "old_id": "1d49f656ae3caa24cef32b491d39516a61f318a0",
      "old_mode": 33188,
      "old_path": "server/core.c",
      "new_id": "72925533a1a57536b5810870d4c1b15df2e06401",
      "new_mode": 33188,
      "new_path": "server/core.c"
    },
    {
      "type": "modify",
      "old_id": "00bd6ffd9f16ab64ad2cfbbd4ddaedb4aa4713fd",
      "old_mode": 33188,
      "old_path": "server/util_script.c",
      "new_id": "75fd7813506373e9ab9df459e23286c26cb89a70",
      "new_mode": 33188,
      "new_path": "server/util_script.c"
    }
  ]
}
