8000 Release v1.2.0-security-fix: Security Fix for Ip Authentication compatible with ES 1.2.0 · DataToKnowledge/elasticsearch-http-basic · GitHub
[go: up one dir, main page]

Skip to content

v1.2.0-security-fix

Due to implementation of how the ip of the client
is obtained it is very easy for an attacker to authenticate
its ip by setting the ip in the 'Host' header or as first ip in the
'X-Forwarded-For' header
Assets 2
Loading
0