Bug - Injectable host header (Security issue)

fixed with Release e2.20.(2|3)