logo

Database

Insufficient data authenticity validation In codeigniter4/framework

Description

CodeIgniter4 allows spoofing of IP address when using proxy

Impact

This vulnerability may allow attackers to spoof their IP address when your server is behind a reverse proxy.

Patches

Upgrade to v4.2.11 or later, and configure Config\App::$proxyIPs.

Workarounds

Do not use $request->getIPAddress().

References

For more information

If you have any questions or comments about this advisory:

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions
FLAT-E0DMB – Vulnerability | Fluid Attacks Database