Skip to content

How shoud we report security issues? #1500

Discussion options

You must be logged in to vote

I appreciate the detailed reports but the more I look at them the less important they seem:

All three issues are of the form "use uWS as the proxy that forwards to a backend server that does X instead of Y". uWS isn't even a proxy and has no such functionality.

One of the three reported issues is that we don't break when host header is missing, how on earth can that be a "vulnerability".

I'm thankful for the nice work made and I have easy fixes that will be made but this is really stretching the wordage "vulnerability" to its breaking point.

One issue is that we trim whitespace between header key and the colon, instead of rejecting the request. This simply is not a vulnerability. The head…

Replies: 7 comments

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Answer selected by uNetworkingAB
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants
Converted from issue

This discussion was converted from issue #1497 on October 24, 2022 16:32.