The Apache “Optionsbleed” security hole explained

Yesterday, we wrote about a new Heartbleed-like vulnerability in the Apache web server. The new security hole can be triggered by a special sort of web request called OPTIONS, and it can leak, or “bleed”, data that isn’t supposed to be revealed… ….thus the name Optionsbleed.

