Pedro Lineu Orso chetcpasswd before 2.4 relies on the X...
High severity
Unreviewed
Published
May 1, 2022
to the GitHub Advisory Database
•
Updated Jan 25, 2024
Description
Published by the National Vulnerability Database
Dec 21, 2006
Published to the GitHub Advisory Database
May 1, 2022
Last updated
Jan 25, 2024
Pedro Lineu Orso chetcpasswd before 2.4 relies on the X-Forwarded-For HTTP header when verifying a client's status on an IP address ACL, which allows remote attackers to gain unauthorized access by spoofing this header.
References