1.12.4 (June 8, 2020)
Changes
http: added headers_with_underscores_action setting to control how client requests with header names containing underscore characters are handled. The options are to allow such headers, reject request or drop headers. The default is to allow headers, preserving existing behavior.
http: fixed CVE-2020-11080 by rejecting HTTP/2 SETTINGS frames with too many parameters.
当前内容版权归 Envoy Proxy 或其关联方所有,如需对内容或内容相关联开源项目进行关注与资助,请访问 Envoy Proxy .