Lucene search

K
friendsofphpOpenJS FoundationFRIENDSOFPHP:CODEIGNITER4:FRAMEWORK:CVE-2022-23556
HistoryDec 22, 2022 - 2:49 a.m.

CVE-2022-23556: Attackers may spoof IP address when using proxy

2022-12-2202:49:45
OpenJS Foundation
github.com
4
cve-2022-23556
spoofing attack
reverse proxy
server security
software vulnerability
proxy configuration
ip address spoofing

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

6.6 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

29.4%

Description Impact This vulnerability may allow attackers to spoof their IP address when your server is behind a reverse proxy. Patches Upgrade to v4.2.11 or later, and configure Config\App::$proxyIPs. Workarounds Do not use $request->getIPAddress(). References https://codeigniter4.github.io/userguide/incoming/request.html#CodeIgniter\HTTP\Request::getIPAddress For more information If you have any questions or comments about this advisory: Open an issue in codeigniter4/CodeIgniter4 Email us at SECURITY.md

Affected configurations

Vulners
Node
codeigniter4frameworkRange<4.2.11
CPENameOperatorVersion
codeigniter4/frameworklt4.2.11

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

6.6 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

29.4%

Related for FRIENDSOFPHP:CODEIGNITER4:FRAMEWORK:CVE-2022-23556