GHSA-j8p3-8m69-2hqq
Dashboard / Vulnerabilities / GHSA-j8p3-8m69-2hqq
Summary: CakePHP allows remote attackers to spoof their IP
Details: The `clientIp` function in CakePHP 3.2.4 and earlier allows remote attackers to spoof their IP via the `CLIENT-IP HTTP` header.
References: https://nvd.nist.gov/vuln/detail/CVE-2016-4793, https://github.com/cakephp/cakephp/commit/908754649f70bab2b1093942e17c9a46a2fcf6c2, https://bakery.cakephp.org/2016/03/13/cakephp_2613_2711_282_3017_3112_325_released.html, https://github.com/cakephp/cakephp, https://support.citrix.com/article/CTX236992, https://www.exploit-db.com/exploits/39813, http://legalhackers.com/advisories/CakePHP-IP-Spoofing-Vulnerability.txt, http://www.securityfocus.com/bid/95846
Affected packages
Package
Name: cakephp/cakephp
Purl: pkg:composer/cakephp/cakephp
Affected ranges
Type: ECOSYSTEM
Events:
