1Panel Version
N/A - This is a tracking issue for a security hardening improvement
Please describe your needs or suggestions for improvements
Description
This issue is to track the security hardening improvement related to the public file-sharing endpoints.
I previously reported that user-supplied X-Forwarded-For headers could affect the rate-limiting key.
The team has decided to handle this as a targeted security hardening by sanitizing and rebuilding the client forwarding headers.
Request
Please consider adding a credit in the release notes / changelog when the fix is released, for example:
Thanks to @mbanyamer for reporting this issue
Notes
- No full exploitation details will be published before the fixed version is released.
- This is not a request for a CVE, just tracking the improvement as suggested.
Thank you.
Please describe the solution you suggest
No response
Additional Information
No response
1Panel Version
N/A - This is a tracking issue for a security hardening improvement
Please describe your needs or suggestions for improvements
Description
This issue is to track the security hardening improvement related to the public file-sharing endpoints.
I previously reported that user-supplied
X-Forwarded-Forheaders could affect the rate-limiting key.The team has decided to handle this as a targeted security hardening by sanitizing and rebuilding the client forwarding headers.
Request
Please consider adding a credit in the release notes / changelog when the fix is released, for example:
Notes
Thank you.
Please describe the solution you suggest
No response
Additional Information
No response