mod_proxy, mod_proxy_http: add options to tackle headers with underscores #558
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
mod_proxy and mod_proxy_http currently pass request headers from user-agent to the backend, (url in
ProxyPass) including those contains underscores. (_)this may cause security issues with certain backends, per Section 17.10 of RFC 9110.
an example of such issue could be described as below:
this patch introduces a new configuration entry
ProxyUnderscoredHeaders, which has 3 possible options listed below, to mitigate such issues.Allow: allow all headers to be passed to the backend including those with underscores (default)Drop: remove headers with underscores in keys and pass remains to the backendReject: reject the request with 400 Bad Request if headers with underscores were foundthe
Allowoption, as default, avoids breaking changes to current behaviour, whileDropandRejectcould be used to help mitigate such security issues.also notice that nginx has a similar option named underscores_in_headers.