GHSA-jg68-vhv3-9r8f
Magento's X-Original-Url header can expose admin url
Quick fix
GHSA-jg68-vhv3-9r8f — openmage/magento-lts: upgrade to the fixed version with the command below.
composer require openmage/magento-lts:^20.16.1Details
### Impact
The admin url can be discovered without prior knowledge of it's location by exploiting the X-Original-Url header on some configurations.
### Patches
The bug comes from the Zend library and is patche by unsetting the header in the bootstrap process.
### Workarounds
Unset the `X-Original-Url` header in the web server configuration.
### References
The activation of these headers is coming from the Zend_Controller module. It appears this has been known to some degree since 2016 - https://peterocallaghan.co.uk/2016/12/magento-poisoning-cache/ (dead link now..)
### Credit
Anees Hyder ( @anees0xdev ) via HackerOne https://hackerone.com/anees0x_dev/hacktivity
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 20.16.1composer require openmage/magento-lts:^20.16.1