Hacker News new | ask | show | jobs
by gtsteve 3024 days ago
Host header attacks aren't exactly new [0]. However it seems that this is deliberately vague to prevent people from exploiting it whilst systems are patched. I note that the CVE details [1] are not yet available, so perhaps the actual issue is a bit more complex.

[0] https://www.acunetix.com/blog/articles/automated-detection-o...

[1] https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-0787