Skip to content

[Feature] Track security hardening for X-Forwarded-For rate-limiting on public file-sharing #13631

Description

@mbanyamer

1Panel Version

N/A - This is a tracking issue for a security hardening improvement

Please describe your needs or suggestions for improvements

Description

This issue is to track the security hardening improvement related to the public file-sharing endpoints.

I previously reported that user-supplied X-Forwarded-For headers could affect the rate-limiting key.
The team has decided to handle this as a targeted security hardening by sanitizing and rebuilding the client forwarding headers.

Request

Please consider adding a credit in the release notes / changelog when the fix is released, for example:

Thanks to @mbanyamer for reporting this issue

Notes

  • No full exploitation details will be published before the fixed version is released.
  • This is not a request for a CVE, just tracking the improvement as suggested.

Thank you.

Please describe the solution you suggest

No response

Additional Information

No response

Metadata

Metadata

Type

No type

Projects

No projects

Relationships

None yet

Development

No branches or pull requests

Issue actions