You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
If an attacker is able to inject a NEL header that requests that Cookie headers be sent in the request_headers report field, then any HttpOnly cookies could also be stolen, which would not be possible with a regular header injection attack.
The text was updated successfully, but these errors were encountered:
If an attacker is able to inject a
NEL
header that requests thatCookie
headers be sent in therequest_headers
report field, then any HttpOnly cookies could also be stolen, which would not be possible with a regular header injection attack.The text was updated successfully, but these errors were encountered: