Описание
request.rb in Web Console before 2.1.3, as used with Ruby on Rails 3.x and 4.x, does not properly restrict the use of X-Forwarded-For headers in determining a client's IP address, which allows remote attackers to bypass the whitelisted_ips protection mechanism via a crafted request.
Ссылки
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.1.2 (включая)
cpe:2.3:a:rubyonrails:web_console:*:*:*:*:*:*:*:*
EPSS
Процентиль: 99%
0.85262
Высокий
4.3 Medium
CVSS2
Дефекты
CWE-284
Связанные уязвимости
EPSS
Процентиль: 99%
0.85262
Высокий
4.3 Medium
CVSS2
Дефекты
CWE-284