Lack of data validation In cakephp/cakephp
Description
CakePHP allows remote attackers to spoof their IP
The clientIp function in CakePHP 3.2.4 and earlier allows remote attackers to spoof their IP via the CLIENT-IP HTTP header.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
packagist | 2.6.13, 2.7.11, 2.8.2, 3.0.17, 3.1.12, 3.2.5 | ||
debian 11 | 2.8.3-1 |
Aliases
1. 2. 3. 4. 5. 6.
References
1. 2. 3. 4. 5. 6.