Reverse Proxy Security
163 incident problems about Reverse Proxy Security. Start with the reviewed ones.
먼저 읽을 가이드
추천 문제
All problems (163)
SECURITY-1234An edge allowlist seems correct but one alternate hostname still exposes the admin surfaceA team locks down an admin interface and later discovers an internal or legacy hostname still reaches the same endpoint without the edge policy.SecurityAdvanced20 minProSECURITY-1229An IP allowlist is present at the edge but admin traffic still leaks throughThe team secures the public hostname and later discovers an alternate internal or legacy hostname still exposes the same admin interface.SecurityAdvanced20 minProSECURITY-1211Federated login breaks only on callbackAn OIDC flow still reaches the provider successfully, but the callback handler rejects the return due to missing browser state.SecurityAdvanced21 minProSECURITY-1210mTLS rotation looks complete but one gateway still failsAn mTLS rotation completes and most gateways recover, but one still rejects peers because its chain trust is incomplete.SecurityAdvanced22 minProSECURITY-1201OIDC issuer update looks complete but one validator still pins the old issuer URLMost auth flows recover after an issuer migration, yet one proxy or sidecar still rejects tokens because it continues to trust the previous issuer location.SecurityAdvanced22 minProSECURITY-1184OIDC login callback breaks behind proxyCommunity fixes focus on the identity provider, but the real break is that the edge proxy is building the wrong callback URL.SecurityAdvanced22 minProSECURITY-1207WAF blocks the obvious payload but a normalized path still reaches the backend through an alternate routeThe rule looks effective in one test, yet another path representation slips through because proxy and WAF normalize differently.SecurityAdvanced23 minProSECURITY-1181Internal registry trust breaksOperators rotate certificates after reading public advice, but only one served path is broken because it omits the intermediate chain.SecurityAdvanced24 minProSECURITY-1366A ban pipeline targets the proxy instead of the attackerA reverse proxy is inserted or reconfigured and automated bans later start punishing the proxy instead of abusive clients.SecurityIntermediate12 minProSECURITY-1362An OpenSearch dashboards login loops after proxy hardeningA reverse proxy is hardened and later users start bouncing between the IdP and dashboards without ever reaching an authenticated session.SecurityIntermediate12 minProSECURITY-1365A Cloudflare Access app is protected on 443 and an alternate admin listener remains publicA team puts an app behind Cloudflare Access and later discovers a side-channel admin port on the same origin is still reachable directly.SecurityAdvanced13 minProSECURITY-1356A Fail2ban or CrowdSec pipeline bans the proxy IPA reverse proxy is inserted and automated bans later begin targeting the proxy instead of the actual abusive clients.SecurityIntermediate13 minProSECURITY-1328A private registry login is successful and image pulls still return 401A private registry login is successful and image pulls still return 401 focuses on Identity And Access and asks the reader to isolate the key signal in docker. Auth redirects across hosts can fail at cookie scope even when credentials and TLS are co...SecurityIntermediate13 minProNETWORK-1399A URL filtering exception covers the main SaaS host and file exports still...A URL filtering exception covers the main SaaS host and file exports still... focuses on incident-response and asks the reader to isolate the key signal in Palo Alto Networks. Feature-specific SaaS traffic often uses shared CDN hostna...NetworkAdvanced13 minProSECURITY-1325A WAF managed rule blocks only one mobile clientA WAF ruleset update is followed by selective failures affecting only one legacy mobile client integration.SecurityIntermediate13 minProSECURITY-1394An NGINX auth_request flow protects GET and POST and one WebDAV verb bypasses...An NGINX auth_request flow protects GET and POST and one WebDAV verb... focuses on Identity And Access and asks the reader to isolate the key signal in NGINX. Rare HTTP verbs often follow older location trees and can bypass newer auth subrequ...SecurityAdvanced13 minProSECURITY-1342An OpenSearch dashboard login loopsA proxy hardening change improves cookie posture and later dashboard users get trapped in a login redirect loop.SecurityIntermediate13 minProSECURITY-1338An OpenSearch Dashboards login loop appearsAn OpenSearch Dashboards login loop appears focuses on Identity And Access and asks the reader to isolate the key signal in NGINX. Modern cookie defaults can break older federated flows even when every credential and endpoint is correct.SecurityIntermediate13 minProSECURITY-1352An OpenSearch SSO redirect loop appears after proxy hardeningA reverse proxy is hardened and later users become trapped in a dashboard login loop even though the identity provider is healthy.SecurityIntermediate13 minProNETWORK-1391A CDN hostname serves HTTP/2 cleanly and API uploads fail over HTTP/3Uploads fail only for clients that negotiate HTTP/3 while ordinary browsing and HTTP/2 API calls remain healthy.NetworkAdvanced14 minPro