-
Type:
Bug
-
Status: Closed
-
Resolution: Duplicate
-
Affects Version/s: 6.2.1 CE GA2
-
Fix Version/s: 6.2.1 CE GA2
-
Component/s: Security Vulnerability
-
Labels:None
The portal is vulnerable to HTTP host header attacks. This vulnerability can be used for web cache poisoning or for password reset poisoning.
- duplicates
-
LPS-49143 Host header validation is not applied consistently and doesn't whitelist IPv6 localhost address [::1]
- Closed