httpd-bugs mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From bugzi...@apache.org
Subject [Bug 56718] Cleanup request Host headers when absolute URI are used
Date Thu, 02 Jul 2015 15:35:28 GMT
https://bz.apache.org/bugzilla/show_bug.cgi?id=56718

--- Comment #5 from Michael Kaufmann <apache-bugzilla@michael-kaufmann.ch> ---
I think that this is an important issue. The patch/bugfix will prevent many
attacks.

The latest patch could be improved: If the request does not have a "Host"
header (HTTP 1.0) and if an absolute URI is used, then a "Host" header should
be added to the request.

-- 
You are receiving this mail because:
You are the assignee for the bug.

---------------------------------------------------------------------
To unsubscribe, e-mail: bugs-unsubscribe@httpd.apache.org
For additional commands, e-mail: bugs-help@httpd.apache.org


Mime
View raw message