Skip to content

gixy: The proxied Host header may be spoofed #10

@mdPlusPlus

Description

@mdPlusPlus

Tool: https://github.com/yandex/gixy

>> Problem: [host_spoofing] The proxied Host header may be spoofed.
Severity: MEDIUM
Description: In most cases "$host" variable are more appropriate, just use it.
Additional info: https://github.com/yandex/gixy/blob/master/docs/en/plugins/hostspoofing.md

Proposed solution:
Replace $http_host variable in setup-proxy-only.sh with $http.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions