Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Explore PassThru vulnerability #49

Open
asimpleidea opened this issue Aug 9, 2022 · 1 comment
Open

Explore PassThru vulnerability #49

asimpleidea opened this issue Aug 9, 2022 · 1 comment
Assignees
Labels
bug Something isn't working

Comments

@asimpleidea
Copy link
Member

https://www.oxeye.io/blog/golang-parameter-smuggling-attack

The project uses ParseUrl to parse the adaptor API base URL. Will dig to see if the project contains any vulnerability related to PassThru

@asimpleidea asimpleidea added the bug Something isn't working label Aug 9, 2022
@asimpleidea asimpleidea self-assigned this Aug 9, 2022
@asimpleidea
Copy link
Member Author

Update: this affects parsing query which only happens in the auto-generated openAPI code.

I will check if openAPI has a new version which fixes this, otherwise I will do it myself.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
None yet
Development

No branches or pull requests

1 participant