Skip to content

2.0.2

Latest

Choose a tag to compare

@github-actions github-actions released this 24 Sep 11:37
· 2 commits to main since this release
2.0.2
0de93d1

2.0.2 stops the PHP proxy from requesting internal hosts, and stops proxy.php from printing exceptions to visitors. Anyone running the proxy should update.

Security

  • The proxy forwarded to any URL given in to, so any visitor could make the server request internal hosts: loopback, private networks, link-local addresses such as the cloud metadata endpoint 169.254.169.254, and internal DNS names. new Proxy() without an HTTP client, and therefore proxy.php, now wraps its client in Symfony's NoPrivateNetworkHttpClient, which refuses targets on private, loopback and link-local addresses and hosts that do not resolve. A refused target is answered with 403 Forbidden and is not requested. The proxy still does not follow redirects; the browser follows them through the proxy again, where the redirect target is checked. Advisory: GHSA-jh6v-vhx2-jh83 · #132 by @CybotTM
  • proxy.php printed the exception and its stack trace to the visitor when forwarding failed. It now logs the exception with error_log() and answers 500 Proxy error. #132 by @CybotTM

Upgrading

  • A client passed to new Proxy($client) is used unchanged: wrap it in NoPrivateNetworkHttpClient yourself (see README).
  • A storage on an internal host now needs an allow list on that wrapper (the allowList argument, symfony/http-client 8.1 or later).

Build and CI

  • Pull requests now run ESLint, the Vitest suite and the Vite build. #131 by @CybotTM

Full Changelog: 2.0.1...2.0.2