Описание
CodeIgniter is a PHP full-stack web framework. This vulnerability may allow attackers to spoof their IP address when the server is behind a reverse proxy. This issue has been patched, please upgrade to version 4.2.11 or later, and configure Config\App::$proxyIPs. As a workaround, do not use $request->getIPAddress().
Ссылки
- PatchThird Party Advisory
- ExploitThird Party Advisory
- PatchThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 4.0.0 (включая) до 4.2.11 (исключая)
cpe:2.3:a:codeigniter:codeigniter:*:*:*:*:*:*:*:*
EPSS
Процентиль: 34%
0.0014
Низкий
7 High
CVSS3
7.5 High
CVSS3
Дефекты
CWE-345
Связанные уязвимости
CVSS3: 7
debian
около 3 лет назад
CodeIgniter is a PHP full-stack web framework. This vulnerability may ...
CVSS3: 7
github
около 3 лет назад
CodeIgniter4 allows spoofing of IP address when using proxy
EPSS
Процентиль: 34%
0.0014
Низкий
7 High
CVSS3
7.5 High
CVSS3
Дефекты
CWE-345