GHSA-j8p3-8m69-2hqq

Suggest an improvement
Source
https://github.com/advisories/GHSA-j8p3-8m69-2hqq
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-j8p3-8m69-2hqq/GHSA-j8p3-8m69-2hqq.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-j8p3-8m69-2hqq
Aliases
Published
2022-05-14T02:19:19Z
Modified
2024-02-18T05:33:47.156722Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
CakePHP allows remote attackers to spoof their IP
Details

The clientIp function in CakePHP 3.2.4 and earlier allows remote attackers to spoof their IP via the CLIENT-IP HTTP header.

Database specific
{
    "nvd_published_at": "2017-01-23T21:59:00Z",
    "cwe_ids": [
        "CWE-20"
    ],
    "severity": "HIGH",
    "github_reviewed": true,
    "github_reviewed_at": "2023-01-14T05:30:42Z"
}
References

Affected packages

Packagist / cakephp/cakephp

Package

Name
cakephp/cakephp
Purl
pkg:composer/cakephp/cakephp

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.2.0
Fixed
2.6.13

Affected versions

2.*

2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.4.10
2.5.0-beta
2.5.0-RC1
2.5.0-RC2
2.5.0
2.5.1
2.5.2
2.5.3
2.5.4
2.5.5
2.5.6
2.5.7
2.5.8
2.5.9
2.6.0-beta
2.6.0-RC1
2.6.0
2.6.1
2.6.2
2.6.3
2.6.4
2.6.5
2.6.6
2.6.7
2.6.8
2.6.9
2.6.10
2.6.11
2.6.12

Packagist / cakephp/cakephp

Package

Name
cakephp/cakephp
Purl
pkg:composer/cakephp/cakephp

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.7.0-rc1
Fixed
2.7.11

Affected versions

2.*

2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.7.9
2.7.10

Packagist / cakephp/cakephp

Package

Name
cakephp/cakephp
Purl
pkg:composer/cakephp/cakephp

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.8.0-rc1
Fixed
2.8.2

Affected versions

2.*

2.8.0-RC1
2.8.0
2.8.1

Packagist / cakephp/cakephp

Package

Name
cakephp/cakephp
Purl
pkg:composer/cakephp/cakephp

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.0.0-rc1
Fixed
3.0.17

Affected versions

3.*

3.0.0-RC1
3.0.0-RC2
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.0.8
3.0.9
3.0.10
3.0.11
3.0.12
3.0.13
3.0.14
3.0.15
3.0.16

Packagist / cakephp/cakephp

Package

Name
cakephp/cakephp
Purl
pkg:composer/cakephp/cakephp

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.1.0-beta1
Fixed
3.1.12

Affected versions

3.*

3.1.0-beta2
3.1.0-RC1
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.1.8
3.1.9
3.1.10
3.1.11

Packagist / cakephp/cakephp

Package

Name
cakephp/cakephp
Purl
pkg:composer/cakephp/cakephp

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.2.0-rc1
Fixed
3.2.5

Affected versions

3.*

3.2.0-RC1
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4