Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-67j6-xv27-w6ww

Опубликовано: 24 окт. 2017
Источник: github
Github: Прошло ревью

Описание

Web Console (Ruby gem) contains whitelisted_ips bypass

request.rb in Web Console before 2.1.3, as used with Ruby on Rails 3.x and 4.x, does not properly restrict the use of X-Forwarded-For headers in determining a client's IP address, which allows remote attackers to bypass the whitelisted_ips protection mechanism via a crafted request.

Пакеты

Наименование

web-console

rubygems
Затронутые версииВерсия исправления

< 2.1.3

2.1.3

EPSS

Процентиль: 99%
0.85262
Высокий

Дефекты

CWE-284

Связанные уязвимости

nvd
больше 10 лет назад

request.rb in Web Console before 2.1.3, as used with Ruby on Rails 3.x and 4.x, does not properly restrict the use of X-Forwarded-For headers in determining a client's IP address, which allows remote attackers to bypass the whitelisted_ips protection mechanism via a crafted request.

EPSS

Процентиль: 99%
0.85262
Высокий

Дефекты

CWE-284