Repository navigation
2.0.2 stops the PHP proxy from requesting internal hosts, and stops proxy.php from printing exceptions to visitors. Anyone running the proxy should update.
Security
- The proxy forwarded to any URL given in
to, so any visitor could make the server request internal hosts: loopback, private networks, link-local addresses such as the cloud metadata endpoint169.254.169.254, and internal DNS names.new Proxy()without an HTTP client, and thereforeproxy.php, now wraps its client in Symfony'sNoPrivateNetworkHttpClient, which refuses targets on private, loopback and link-local addresses and hosts that do not resolve. A refused target is answered with403 Forbiddenand is not requested. The proxy still does not follow redirects; the browser follows them through the proxy again, where the redirect target is checked. Advisory: GHSA-jh6v-vhx2-jh83 · #132 by @CybotTM proxy.phpprinted the exception and its stack trace to the visitor when forwarding failed. It now logs the exception witherror_log()and answers500 Proxy error. #132 by @CybotTM
Upgrading
- A client passed to
new Proxy($client)is used unchanged: wrap it inNoPrivateNetworkHttpClientyourself (see README). - A storage on an internal host now needs an allow list on that wrapper (the
allowListargument, symfony/http-client 8.1 or later).
Build and CI
Full Changelog: 2.0.1...2.0.2