Lucene search

K
prionPRIOn knowledge basePRION:CVE-2024-21494
HistoryFeb 17, 2024 - 5:15 a.m.

Authentication flaw

2024-02-1705:15:00
PRIOn knowledge base
www.prio-n.com
7
vulnerability
authentication bypass
spoofing
x-forwarded-for
input sanitization
user identity module
unauthorized access
trust flaw

7 High

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

15.8%

All versions of the package github.com/greenpau/caddy-security are vulnerable to Authentication Bypass by Spoofing via the X-Forwarded-For header due to improper input sanitization. An attacker can spoof an IP address used in the user identity module (/whoami API endpoint). This could lead to unauthorized access if the system trusts this spoofed IP address.

7 High

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

15.8%

Related for PRION:CVE-2024-21494