New Attack Bypasses HTTP/2 Security for Arbitrary Cross-Site Scripting (cybersecuritynews.com)
from kid@sh.itjust.works to cybersecurity@sh.itjust.works on 27 May 17:55
https://sh.itjust.works/post/38854284

#cybersecurity

threaded - newest

cron@feddit.org on 27 May 18:45 collapse

Not going to downplay the vulnerability, but the key requirement for this attack is that both attacker and the victim domain must both be present in the SSL certificate’s SAN entries. This is something that can happen, e.g. with some web hosters, but is probably pretty rare.