CVE-2015-3224

EPSS 85.3%

Web Console (Ruby gem) contains whitelisted_ips bypass

Published: 10/24/2017Modified: 12/3/2024
Also known as:GHSA-67j6-xv27-w6ww

Description

request.rb in Web Console before 2.1.3, as used with Ruby on Rails 3.x and 4.x, does not properly restrict the use of X-Forwarded-For headers in determining a client's IP address, which allows remote attackers to bypass the whitelisted_ips protection mechanism via a crafted request.

Affected packages (1)

References (7)