TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Mitigating the HTTPoxy Vulnerability with Nginx

51 点作者 kgogolek将近 9 年前

3 条评论

rahkiin将近 9 年前
&gt; The vulnerability was mentioned on the NGINX mailing list in July, 2013, by Jonathan Matthews.<p>Wow, that is long ago. Why isn&#x27;t this mitigated earlier? The attack is very simple.
评论 #12128176 未加载
drdaeman将近 9 年前
There are mentions of Python... Does this affect WSGI applications, in particular, uWSGI?<p>AFAIK, uWSGI somewhat resembles but doesn&#x27;t emulate CGI (unlike how FastCGI works), and WSGI application&#x27;s `environ` parameter isn&#x27;t related to `os.environ`, so it should be safe. But I may be mistaken here...
评论 #12128422 未加载
jimjag将近 9 年前
NGINX should have really applied for a CVE instead of pretending that they are immune.
评论 #12128651 未加载