Описание
go-chi chi versions >= 5.2.1 and before 5.3.0 contain an IP spoofing vulnerability in the RealIP middleware, which blindly trusts the first (leftmost) value of the X-Forwarded-For HTTP header. A remote attacker can bypass IP-based access control lists and rate-limiting mechanisms, and forge log entries, by supplying a spoofed IP address in the X-Forwarded-For header. The issue is fixed in version 5.3.0.
A flaw was found in the go-chi chi RealIP middleware. This vulnerability allows a remote attacker to spoof their IP address by manipulating the X-Forwarded-For HTTP header. By exploiting this, an attacker can bypass IP-based access control lists and rate-limiting mechanisms, and forge log entries, potentially leading to unauthorized access or misattribution of actions.
Отчет
An IP spoofing flaw exists in go-chi/chi's RealIP middleware. When parsing incoming HTTP requests, the middleware blindly trusts the leftmost IP address in the X-Forwarded-For header without verifying proxy chain trust. Remote unauthenticated attackers can supply arbitrary client IP addresses to bypass IP-based access control lists (ACLs), evade rate-limiting rules, or forge audit trail logs, posing a Low impact to confidentiality and integrity.
Меры по смягчению последствий
Do not rely on the RealIP middleware when accepting connections from untrusted networks. Instead, configure an upstream reverse proxy (such as NGINX or HAProxy) to overwrite or sanitize client-supplied X-Forwarded-For headers before forwarding traffic to the application.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Cryostat 4 | cryostat/cryostat-storage-rhel9 | Fix deferred | ||
| External Secrets Operator for Red Hat OpenShift | external-secrets-operator/bitwarden-sdk-server-rhel9 | Fix deferred | ||
| Gatekeeper 3 | gatekeeper/gatekeeper-rhel9 | Fix deferred | ||
| Logging Subsystem for Red Hat OpenShift | openshift-logging/opa-openshift-rhel9 | Not affected | ||
| Migration Toolkit for Applications 8 | mta/mta-hub-rhel9 | Fix deferred | ||
| Multicluster Engine for Kubernetes | multicluster-engine/assisted-image-service-rhel8 | Not affected | ||
| Multicluster Engine for Kubernetes | multicluster-engine/assisted-image-service-rhel9 | Not affected | ||
| OpenShift Pipelines | openshift-pipelines-client | Fix deferred | ||
| OpenShift Pipelines | openshift-pipelines/pipelines-opc-rhel9 | Fix deferred | ||
| OpenShift Serverless | openshift-serverless-1/kn-plugin-event-sender-rhel9 | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
6.5 Medium
CVSS3
Связанные уязвимости
go-chi chi versions >= 5.2.1 and before 5.3.0 contain an IP spoofing vulnerability in the RealIP middleware, which blindly trusts the first (leftmost) value of the X-Forwarded-For HTTP header. A remote attacker can bypass IP-based access control lists and rate-limiting mechanisms, and forge log entries, by supplying a spoofed IP address in the X-Forwarded-For header. The issue is fixed in version 5.3.0.
go-chi chi versions >= 5.2.1 and before 5.3.0 contain an IP spoofing vulnerability in the RealIP middleware, which blindly trusts the first (leftmost) value of the X-Forwarded-For HTTP header. A remote attacker can bypass IP-based access control lists and rate-limiting mechanisms, and forge log entries, by supplying a spoofed IP address in the X-Forwarded-For header. The issue is fixed in version 5.3.0.
go-chi chi versions >= 5.2.1 and before 5.3.0 contain an IP spoofing v ...
go-chi chi versions >= 5.2.1 and before 5.3.0 contain an IP spoofing vulnerability in the RealIP middleware, which blindly trusts the first (leftmost) value of the X-Forwarded-For HTTP header. A remote attacker can bypass IP-based access control lists and rate-limiting mechanisms, and forge log entries, by supplying a spoofed IP address in the X-Forwarded-For header. The issue is fixed in version 5.3.0.
EPSS
6.5 Medium
CVSS3