Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h395-qcrw-5vmq

Опубликовано: 23 июн. 2021
Источник: github
Github: Прошло ревью
CVSS3: 7.1

Описание

Inconsistent Interpretation of HTTP Requests in github.com/gin-gonic/gin

When gin is exposed directly to the internet, a client's IP can be spoofed by setting the X-Forwarded-For header. This affects all versions of package github.com/gin-gonic/gin under 1.7.7.

Пакеты

Наименование

github.com/gin-gonic/gin

go
Затронутые версииВерсия исправления

< 1.7.7

1.7.7

EPSS

Процентиль: 58%
0.0036
Низкий

7.1 High

CVSS3

Дефекты

CWE-113
CWE-444

Связанные уязвимости

CVSS3: 7.1
ubuntu
около 5 лет назад

This affects all versions of package github.com/gin-gonic/gin. When gin is exposed directly to the internet, a client's IP can be spoofed by setting the X-Forwarded-For header.

CVSS3: 7.1
redhat
около 6 лет назад

This affects all versions of package github.com/gin-gonic/gin. When gin is exposed directly to the internet, a client's IP can be spoofed by setting the X-Forwarded-For header.

CVSS3: 7.1
nvd
около 5 лет назад

This affects all versions of package github.com/gin-gonic/gin. When gin is exposed directly to the internet, a client's IP can be spoofed by setting the X-Forwarded-For header.

CVSS3: 7.1
debian
около 5 лет назад

This affects all versions of package github.com/gin-gonic/gin. When gi ...

EPSS

Процентиль: 58%
0.0036
Низкий

7.1 High

CVSS3

Дефекты

CWE-113
CWE-444