mdPlusPlus / lempstack

LEMP Installer for Debian/Ubuntu - Linux, NGINX, MySQL, PHP
MIT License
7 stars 1 forks source link

gixy: The proxied Host header may be spoofed #10

Open mdPlusPlus opened 1 year ago

mdPlusPlus commented 1 year ago

Tool: https://github.com/yandex/gixy

>> Problem: [host_spoofing] The proxied Host header may be spoofed.
Severity: MEDIUM
Description: In most cases "$host" variable are more appropriate, just use it.
Additional info: https://github.com/yandex/gixy/blob/master/docs/en/plugins/hostspoofing.md

Proposed solution:
Replace $http_host variable in setup-proxy-only.sh with $http.