Логотип exploitDog
bind:CVE-2025-66508
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-66508

Количество 2

Количество 2

nvd логотип

CVE-2025-66508

2 месяца назад

1Panel is an open-source, web-based control panel for Linux server management. Versions 2.0.14 and below use Gin's default configuration which trusts all IP addresses as proxies (TrustedProxies = 0.0.0.0/0), allowing any client to spoof the X-Forwarded-For header. Since all IP-based access controls (AllowIPs, API whitelists, localhost-only checks) rely on ClientIP(), attackers can bypass these protections by simply sending X-Forwarded-For: 127.0.0.1 or any whitelisted IP. This renders all IP-based security controls ineffective. This issue is fixed in version 2.0.14.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-7cqv-qcq2-r765

2 месяца назад

1Panel IP Access Control Bypass via Untrusted X-Forwarded-For Headers

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-66508

1Panel is an open-source, web-based control panel for Linux server management. Versions 2.0.14 and below use Gin's default configuration which trusts all IP addresses as proxies (TrustedProxies = 0.0.0.0/0), allowing any client to spoof the X-Forwarded-For header. Since all IP-based access controls (AllowIPs, API whitelists, localhost-only checks) rely on ClientIP(), attackers can bypass these protections by simply sending X-Forwarded-For: 127.0.0.1 or any whitelisted IP. This renders all IP-based security controls ineffective. This issue is fixed in version 2.0.14.

CVSS3: 6.5
0%
Низкий
2 месяца назад
github логотип
GHSA-7cqv-qcq2-r765

1Panel IP Access Control Bypass via Untrusted X-Forwarded-For Headers

CVSS3: 6.5
0%
Низкий
2 месяца назад

Уязвимостей на страницу