Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:25500
HistoryMay 27, 2020 - 5:11 a.m.

IP Whitelisting Bypass

2020-05-2705:11:54
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
5

EPSS

0.002

Percentile

64.8%

verbb/knock-knock is vulnerable to IP Whitelisting Bypass. It is due to the use of a flawed IP-Whitelisting mechanism of getting User IP , allowing bypass of IP whitelisting through X-Forwarded-For header manipulation.

EPSS

0.002

Percentile

64.8%

Related for VERACODE:25500