We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
1 parent bb0104d commit 61864a8Copy full SHA for 61864a8
SECURITY.md
@@ -33,6 +33,17 @@ acknowledge your responsible disclosure, if you wish.
33
34
## History
35
36
+> A URL with a specified but empty port can be used to bypass authorization
37
+> checks.
38
+
39
+- **Reporter credits**
40
+ - Rohan Sharma
41
+ - GitHub: [@r0hansh](https://github.com/r0hansh)
42
+- Huntr report: https://www.huntr.dev/bounties/55fd06cd-9054-4d80-83be-eb5a454be78c/
43
+- Fixed in: 1.5.8
44
45
+---
46
47
> A specially crafted URL with empty userinfo and no host can be used to bypass
48
> authorization checks.
49
0 commit comments