PT-2026-95596 · Git · Saleor
CVSS v3.1
3.7
Low
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Saleor versions prior to 3.20.119
Saleor versions prior to 3.21.55
Saleor versions prior to 3.22.48
Saleor versions prior to 3.23.15
Description
An issue exists in the
get client ip() function within the saleor/account/throttling.py file. A remote attacker can manipulate the request to spoof the client IP address, which may lead to the improper restriction of excessive authentication attempts. This occurs because the REAL IP ENVIRON setting can bypass the get client ip() function, and the system may not correctly handle X-Forwarded-For (XFF) headers, which are used to identify the originating IP address of a client connecting to a web server through an HTTP proxy.Recommendations
Ensure that X-Forwarded-For (XFF) headers are configured properly in the deployment environment to prevent IP spoofing.
As a temporary mitigation, restrict or carefully monitor the use of the
get client ip() function in saleor/account/throttling.py until a formal patch is merged.Exploit
Fix
Improper Restriction of Excessive Authentication Attempts
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Saleor