GHSA-xhfx-hgmf-v6vp

    Dashboard / Vulnerabilities / GHSA-xhfx-hgmf-v6vp

    GHSA-xhfx-hgmf-v6vp

    Published: 10 Mar 2021Last Modified: 8 Jul 2026

    Summary: October CMS vulnerable to Potential Host Header Poisoning on misconfigured servers

    Details: ### Impact When running on servers that are configured to accept a wildcard as a hostname (i.e. the server routes any request, regardless of the HOST header to an October CMS instance) the potential exists for Host Header Poisoning attacks to succeed. See the following resources for more information on Host Header Poisoning: - https://portswigger.net/web-security/host-header - https://dzone.com/articles/what-is-a-host-header-attack ### Patches A feature has been added in v1.1.2 to allow a set of trusted hosts to be specified in the application. ### Workarounds - Apply https://github.com/octobercms/library/commit/f86fcbcd066d6f8b939e8fe897409d152b11c3c6 & https://github.com/octobercms/october/commit/f638d3f78cfe91d7f6658820f9d5e424306a3db0 to your installation manually if unable to upgrade to v1.1.2. - Check that the configuration setting `cms.linkPolicy` is set to `force`. ### Alternative Workaround Check to make sure that your web server does not accept any hostname when serving your web application. 1. Add an entry called `testing.tld` to your computer's host file and direct it to your server's IP address 2. Open the address `testing.tld` in your web browser 3. Make sure an October CMS website is not available at this address If an October CMS website is returned, configure your webserver to only allow known hostnames. If you require assistance with this, please contact your server administrator. ### References Reported by [Abdullah Hussam](https://github.com/ahussam) ### For More Information If you have any questions or comments about this advisory: * Email us at [[email protected]](mailto:[email protected]) ### Threat Assessment <img width="1108" alt="Screen Shot 2021-01-15 at 4 12 57 PM" src="https://user-images.githubusercontent.com/7253840/104783859-92fb3600-574c-11eb-9e21-c0dc05d230a9.png">

    Affected packages

    Package

    Name: october/backend

    Purl: pkg:composer/october/backend

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -1.1.2

    Affected versions

    v1.0.319
    v1.0.320
    v1.0.321
    v1.0.322
    v1.0.323
    v1.0.324
    v1.0.325
    v1.0.326
    v1.0.327
    v1.0.328
    v1.0.329
    v1.0.330
    v1.0.331
    v1.0.332
    v1.0.333
    v1.0.334
    v1.0.335
    v1.0.336
    v1.0.337
    v1.0.338
    v1.0.339
    v1.0.340
    v1.0.341
    v1.0.342
    v1.0.343
    v1.0.344
    v1.0.345
    v1.0.346
    v1.0.347
    v1.0.348
    v1.0.349
    v1.0.350
    v1.0.351
    v1.0.352
    v1.0.353
    v1.0.354
    v1.0.355
    v1.0.356
    v1.0.357
    v1.0.358
    v1.0.359
    v1.0.360
    v1.0.361
    v1.0.362
    v1.0.363
    v1.0.364
    v1.0.365
    v1.0.366
    v1.0.367
    v1.0.368
    v1.0.369
    v1.0.370
    v1.0.371
    v1.0.372
    v1.0.373
    v1.0.374
    v1.0.375
    v1.0.376
    v1.0.377
    v1.0.378
    v1.0.379
    v1.0.380
    v1.0.381
    v1.0.382
    v1.0.383
    v1.0.384
    v1.0.385
    v1.0.386
    v1.0.387
    v1.0.388
    v1.0.389
    v1.0.390
    v1.0.391
    v1.0.392
    v1.0.393
    v1.0.394
    v1.0.395
    v1.0.396
    v1.0.397
    v1.0.398
    v1.0.399
    v1.0.400
    v1.0.401
    v1.0.402
    v1.0.403
    v1.0.404
    v1.0.405
    v1.0.406
    v1.0.407
    v1.0.408
    v1.0.409
    v1.0.410
    v1.0.411
    v1.0.412
    v1.0.413
    v1.0.414
    v1.0.415
    v1.0.416
    v1.0.417
    v1.0.418
    v1.0.419
    v1.0.420
    v1.0.421
    v1.0.422
    v1.0.423
    v1.0.424
    v1.0.425
    v1.0.426
    v1.0.427
    v1.0.428
    v1.0.429
    v1.0.430
    v1.0.431
    v1.0.432
    v1.0.433
    v1.0.434
    v1.0.435
    v1.0.436
    v1.0.437
    v1.0.438
    v1.0.439
    v1.0.440
    v1.0.441
    v1.0.442
    v1.0.443
    v1.0.444
    v1.0.445
    v1.0.446
    v1.0.447
    v1.0.448
    v1.0.449
    v1.0.450
    v1.0.451
    v1.0.452
    v1.0.453
    v1.0.454
    v1.0.455
    v1.0.456
    v1.0.457
    v1.0.458
    v1.0.459
    v1.0.460
    v1.0.461
    v1.0.462
    v1.0.463
    v1.0.464
    v1.0.465
    v1.0.466
    v1.0.467
    v1.0.468
    v1.0.469
    v1.0.470
    v1.0.471
    v1.0.472
    v1.0.473
    v1.0.474
    v1.0.475
    v1.0.476

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-xhfx-hgmf-v6vp | CVE-DB