Chenjp opened a new pull request, #993:
URL: https://github.com/apache/tomcat/pull/993

   Remote ip valve / filter may populate a malformed header value into request 
attribute without basic validation, those unexpected remote ip/host values may 
mislead downstream components.
   
   Per de-facto standards, ignore malformed xff header rather than Raise 400.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to