Reverse Proxy Security
163 incident problems about Reverse Proxy Security. Start with the reviewed ones.
먼저 읽을 가이드
추천 문제
All problems (163)
SECURITY-1321An AWS ALB OIDC flow loops (alb-oidc-callback-hostname-drift-after-proxy-change)An AWS ALB OIDC flow loops (alb-oidc-callback-hostname-drift-after-proxy... focuses on Identity And Access and asks the reader to isolate the key signal in AWS. OIDC loops often come from callback identity drift rather than from bad user cr...SecurityAdvanced16 minProSECURITY-1303Cloudflare Access protects the app generally and one cached path reaches the origin without identity headersAn origin trusts CF Access headers and later one static-like route starts reaching it without the expected identity context.SecurityAdvanced16 minProSECURITY-1293A WAF rule tuned for the main hostname still blocks the canary pathA canary environment behind the same WAF behaves differently even after the rule was tuned against production traffic.SecurityAdvanced17 minProSECURITY-1231A browser login loop persists after successful OIDC callbackOne hostname or browser completes the login flow and another loops forever even though the provider logs show success.SecurityAdvanced18 minProSECURITY-1275A WAF tune fixes the primary hostname but the same application still fails on a second hostnameA false positive fix is validated on the main public route and users still break through a legacy or alternate hostname.SecurityAdvanced18 minProSECURITY-1265mTLS succeeds for one hostname but fails for another on the same serviceSecurity incident scenario used for structured troubleshooting practice.SecurityAdvanced18 minProSECURITY-1270mTLS succeeds for one hostname but fails for another on the same serviceA service behind one proxy works for its main hostname and starts failing trust or hostname checks on another alias.SecurityAdvanced18 minProSECURITY-1273One hostname behind the same proxy passes mTLS while another failsA service behind one proxy works on its primary hostname and fails on an alternate alias that was assumed to be equivalent.SecurityAdvanced18 minProSECURITY-1224WAF rollback looks complete but one hostname still enforces the old ruleA temporary block is reverted and most traffic returns to normal, but one API hostname still rejects the old pattern.SecurityAdvanced18 minProSECURITY-1219WAF rule rollback looks complete but one API hostname still enforces the old behaviorA temporary block is reverted and most traffic returns to normal, but one API hostname still rejects the old pattern.SecurityAdvanced18 minProSECURITY-1263A WAF blocks legitimate traffic only (alternate-proxy-chain-triggers-different-waf-signals)A WAF blocks legitimate traffic only (alternate-proxy-chain-triggers... focuses on reverse-proxy-security and asks the reader to isolate the key signal in Azure. A WAF rule tuned for one header and proxy shape can still fail on alternate h...SecurityAdvanced19 minProSECURITY-1268A WAF blocks legitimate traffic only (alternate-proxy-chain-triggers-different-waf-signals)A WAF blocks legitimate traffic only (alternate-proxy-chain-triggers... focuses on reverse-proxy-security and asks the reader to isolate the key signal in Azure. A WAF rule tuned for one header and proxy shape can still fail on alternate h...SecurityAdvanced19 minProSECURITY-1259An allowlist protects the main admin hostname but a second hostname still reaches the same backend through another proxy chainThe edge policy works on the documented URL, yet another hostname bypasses it because the backend is still exposed through a different path.SecurityAdvanced19 minProSECURITY-1214CSP looks right but federated login popup still failsA CSP hardening change seems safe until popup or embedded identity flows start failing for some users.SecurityAdvanced19 minProSECURITY-1216Secure cookie and redirect settings look correct but one browser still loopsFederated login works in one hostname path but another branded hostname falls into a redirect loop after successful auth.SecurityAdvanced19 minProSECURITY-1218Abuse detection misses distributed attacksAn application sometimes receives traffic through the CDN and sometimes directly, but logging logic always trusts the forwarded IP header.SecurityAdvanced20 minProSECURITY-1223Abuse detection misses distributed attacksAn application sometimes receives traffic via CDN and sometimes directly, but the detector always trusts the same forwarded header.SecurityAdvanced20 minProSECURITY-1249An admin surface seems protected by an edge allowlist but an alternate hostname still bypasses it through another proxy chainThe main route is locked down, yet the same backend remains reachable through a secondary hostname that never traverses the allowlisted edge path.SecurityAdvanced20 minProSECURITY-1244An edge allowlist looks correct but an alternate hostname still exposes the admin surfaceA team secures the public admin entry and later finds an internal or legacy hostname still exposes it without the same edge restrictions.SecurityAdvanced20 minProSECURITY-1254An edge allowlist seems correct but an alternate hostname still bypasses it through another proxy chainThe main route is protected, yet the same backend remains reachable through a secondary hostname that never traverses the allowlisted edge path.SecurityAdvanced20 minPro