Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fixed HTTPoxy vulnerability ref #251 #252

Closed
wants to merge 2 commits into from
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 3 additions & 0 deletions fastcgi_params
Original file line number Diff line number Diff line change
Expand Up @@ -30,3 +30,6 @@ fastcgi_param REDIRECT_STATUS 200;
fastcgi_param HTTPS $fastcgi_https if_not_empty;
## For Nginx versions below 1.1.11 uncomment the line below after commenting out the above.
#fastcgi_param HTTPS $fastcgi_https;

## Fix HTTPoxy vulnerability https://httpoxy.org/#mitigate-nginx
fastcgi_param HTTP_PROXY "";
6 changes: 6 additions & 0 deletions sites-available/example.com.conf
Original file line number Diff line number Diff line change
Expand Up @@ -56,6 +56,12 @@ server {
## Uncomment if you're proxying to Apache for handling PHP.
#proxy_http_version 1.1; # keep alive to the Apache upstream

# Allow "Well-Known URIs" as per RFC 5785.
# Necessary for Let’s Encrypt validation server.
location ~* ^/.well-known/ {
allow all;
}

################################################################
### Generic configuration: for most Drupal 7 sites.
################################################################
Expand Down