RSS   Vulnerabilities for 'Web console'   RSS

2015-07-26
 
CVE-2015-3224

 

 
request.rb in Web Console before 2.1.3, as used with Ruby on Rails 3.x and 4.x, does not properly restrict the use of X-Forwarded-For headers in determining a client's IP address, which allows remote attackers to bypass the whitelisted_ips protection mechanism via a crafted request.

 

 >>> Vendor: Rubyonrails 12 Products
Ruby on rails
Rails
Ruby on ra2000ils
Jquery-rails
Jquery-ujs
Web console
Html sanitizer
Active job
Active storage
Actionview
Actionpack page-caching
Active resource


Copyright 2024, cxsecurity.com

 

Back to Top