Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g49q-m8rg-qhw4

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

OpenAsset Digital Asset Management (DAM) through 12.0.19 does not correctly determine the HTTP request's originating IP address, allowing attackers to spoof it using X-Forwarded-For in the header, by supplying localhost address such as 127.0.0.1, effectively bypassing all IP address based access controls.

OpenAsset Digital Asset Management (DAM) through 12.0.19 does not correctly determine the HTTP request's originating IP address, allowing attackers to spoof it using X-Forwarded-For in the header, by supplying localhost address such as 127.0.0.1, effectively bypassing all IP address based access controls.

EPSS

Процентиль: 74%
0.00843
Низкий

Дефекты

CWE-290

Связанные уязвимости

CVSS3: 7.5
nvd
около 5 лет назад

OpenAsset Digital Asset Management (DAM) through 12.0.19 does not correctly determine the HTTP request's originating IP address, allowing attackers to spoof it using X-Forwarded-For in the header, by supplying localhost address such as 127.0.0.1, effectively bypassing all IP address based access controls.

EPSS

Процентиль: 74%
0.00843
Низкий

Дефекты

CWE-290