PT-2023-29245 · Pretix · Pretix

CVE-2023-44463

·

Publicado

2023-10-02

·

Atualizado

2024-09-23

CVSS v4.0

6.9

Média

VetorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions pretix versions prior to 2023.7.1
Description An issue was discovered in the application where incorrect parsing of configuration files causes it to trust unchecked X-Forwarded-For headers even though it has not been configured to do so. This can lead to IP address spoofing by users of the application.
Recommendations For versions prior to 2023.7.1, update to version 2023.7.1 or later to resolve the issue. As a temporary workaround, consider restricting the trust of X-Forwarded-For headers until a patch is applied.

Exploit

Correção

Authentication Bypass by Spoofing

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-44463
GHSA-J9GQ-W73W-9H6C
PYSEC-2023-187

Produtos afetados

Pretix