Lucene search

K
osvGoogleOSV:GHSA-WXVR-QQM7-6H65
HistoryMay 24, 2022 - 5:18 p.m.

Knock Knock plugin IP Whitelist bypass via an X-Forwarded-For HTTP header

2022-05-2417:18:42
Google
osv.dev
3
craft cms
knock knock plugin
ip whitelist
x-forwarded-for

AI Score

7

Confidence

High

EPSS

0.002

Percentile

64.8%

The Knock Knock plugin before 1.2.8 for Craft CMS allows IP Whitelist bypass via an X-Forwarded-For HTTP header.

AI Score

7

Confidence

High

EPSS

0.002

Percentile

64.8%

Related for OSV:GHSA-WXVR-QQM7-6H65