|
|
|
|
|
by the_mitsuhiko
3914 days ago
|
|
The situation here is that people did not read the docs. Do you think they will start to read the docs for the proxy pass? Aside of that, you cannot securely detect this because what it actually does is passing in a header which if not reliably set can be forged. |
|
It's not exactly uncommon that people leak errors, remote code execution is another level though. It doesn't hurt to be careful with such a feature.