Thursday, March 7, 2019

New vulnerability on the NVD: CVE-2018-11783

sslheaders plugin extracts information from the client certificate and sets headers in the request based on the configuration of the plugin. The plugin doesn't strip the headers from the request in some scenarios. This problem was discovered in versions 6.0.0 to 6.0.3, 7.0.0 to 7.1.5, and 8.0.0 to 8.0.1.

Published at: March 07, 2019 at 08:29PM
View on website

No comments:

Post a Comment