Initial debug-host handler implementation could leak information and facilitate denial of service
Description
Published to the GitHub Advisory Database
Jan 27, 2023
Reviewed
Jan 27, 2023
Last updated
Jan 27, 2023
Impact
version 1.5.0 and 1.6.0 when using the new
debug-host
feature could expose unnecessary information about the hostPatches
Use 1.6.1 or newer
Workarounds
Downgrade to 1.4.0 or set
debug-host
to emptyReferences
fortio/proxy#38
Q&A https://github.com/fortio/proxy/discussions
References