PT-2026-61693 · Glance · Glance
CVSS v4.0
8.2
High
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Glance version 0.8.5
Description
An IP address spoofing issue exists in the authentication handler when the server proxied option is enabled. Unauthenticated attackers can bypass brute-force lockout protections by providing arbitrary values in the
X-Forwarded-For request header. By manipulating the leftmost value of this header, attackers can make each login attempt appear to come from a different IP address, preventing the per-IP failed-login counter from triggering a lockout and allowing unlimited credential guessing against the authentication endpoint.Recommendations
For version 0.8.5, disable the server proxied option as a temporary mitigation to prevent the bypass of brute-force protections.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Glance