EC-Release / sdk

The Agent SDK
Other
4 stars 7 forks source link

Gateway IP Filter Mechanism Bypass via HTTP Headers #121

Open ayasuda2OO3 opened 4 years ago

ayasuda2OO3 commented 4 years ago

GE Digital Security Vulnerability Report [3704]

The report had found that feature WhiteList/BlackList be vulnerable to Loopback addresses (localhost, 127.0.0.1, etc.) it further recommended to limit the usage to a range of pre-defined proxy services to reduce the risk of illegal usage from abusers.