HTTP QUERY Method: The Grey Zone Between GET And POST., (Fri, Sep 18th)
ID: c2a4b1d6-5f45-5fc5-b245-0396c8c6ef71
STIX ID: report--c2a4b1d6-5f45-5fc5-b245-0396c8c6ef71
Feed Name: SANS ISC Diary
Threat Score
The IETF published RFC 10008 introducing a new HTTP method, QUERY, which places the request query in the body and is defined as safe and idempotent; inconsistent support across clients, servers, frameworks, CDNs and security controls can lead to WAF/inspection bypasses, cache poisoning, and CSRF gaps, so defenders should update method allowlists, regexes and caching/keying rules and audit logs for QUERY traffic.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
