Issue metadata
Sign in to add a comment
|
Security: Information disclosure through http cache
Reported by
ma7h1a...@gmail.com,
Apr 27 2018
|
||||||||||||||||||
Issue descriptiononline demo: http://176.122.169.50/static/guest.html
,
Apr 27 2018
Here's what I think you're saying here: 1> If there's a resource for which the server makes an Access Control decision based on the HTTP Referer header, AND 2> That resource is cacheable, AND 3> The server fails to properly include a Vary: Referer response header on that response, THEN Then the browser will freely use that resource for subsequent requests, despite the fact that the server would have returned a different resource had the resource not been in the cache. Is that correct? If so, this is absolutely working-as-expected. Servers who vary responses based on request headers must indicate that they've done so using the Vary response header.
,
Aug 4
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||
Comment 1 by ma7h1a...@gmail.com
, Apr 27 2018268 bytes
268 bytes View Download