[v7.5.x] Fix for CVE-2022-21702 (#226)

Fix for CVE-2022-21702
This commit is contained in:
Marcus Efraimsson
2022-01-21 16:43:04 +01:00
committed by GitHub
parent 7b6cadf646
commit 27726868b3
7 changed files with 79 additions and 2 deletions
+7 -1
View File
@@ -71,5 +71,11 @@ func NewApiPluginProxy(ctx *models.ReqContext, proxyPath string, route *plugins.
}
}
return &httputil.ReverseProxy{Director: director}
return &httputil.ReverseProxy{Director: director, ModifyResponse: modifyResponse}
}
func modifyResponse(resp *http.Response) error {
proxyutil.SetProxyResponseHeaders(resp.Header)
return nil
}