PHP's http:// stream wrapper sent Authorization, Cookie and Proxy-Authorization to any host a redirect pointed at, the bug curl fixed in 2018.

4 points•amvalex•6 days ago•1 comment•

1 comment

amvalex6 days ago
Author here, I wrote the fix with Jakub Zelenka. Happy to take any question you may have about this CVE.

Read the full thread on Hacker News →

Related stories