Headers Host Header Injection

Using untrusted Host header for generating dynamic URLs can result in web cache and or password reset poisoning.

IndexedPublic repositoryMediumMedium confidenceVerifiedLGPL-3.0-onlyJS
greprules fetch gitlab-sast-rules-lgpl-javascript-headers-rule-host-header-injection --engine opengrep

Description

Using untrusted Host header for generating dynamic URLs can result in web cache and or password reset poisoning.