-
Bug
-
Resolution: Fixed
-
Minor
-
Future Dev
The repository url is by definition grabbing the contents of a url on behalf of a user so the data can't be trusted. If a site has a proxy then at the moment it honors proxybypass to decide if to use the proxy or not, but proxybypass is potentially susceptible to dns rebind attacks as well as simply being mis configured. We'd had this appear on a couple pen tests and it's always been minor but it keeps coming up so worth fixing.
- has a non-specific relationship to
-
MDL-70861 Logical inconsistency between ignoresecurity and curl with a proxy
-
- Open
-