PHP's http:// stream wrapper sent Authorization, Cookie and Proxy-Authorization to any host a redirect pointed at, the bug curl fixed in 2018.
1 comment
amvalex6 days ago
Author here, I wrote the fix with Jakub Zelenka. Happy to take any question you may have about this CVE.
Read the full thread on Hacker News →
Related stories
- Hacker News · 1 points · 6 days ago
- Porting Extensions to PHP 8seidengroup.comLobsters · 5 points · almost 6 years ago
- TCP SACK PANIC - Kernel vulnerabilities - CVE-2019-11477, CVE-2019-11478 & CVE-2019-11479access.redhat.comLobsters · 1 points · over 7 years ago
- PHP 4.1.1 Simulator: A jsfiddle-style edit-run page for 2001 era PHPsimphp.infinitefun.comHacker News · 1 points · 4 days ago
- Hacker News · 1 points · 4 days ago
- Typed properties in PHPstitcher.ioLobsters · 7 points · over 7 years ago