An issue was discovered in Kurmi Provisioning Suite 7.9.0.33. If an X-Forwarded-For header is received during authentication, the Kurmi application will record the (possibly forged) IP address mentioned in that header rather than the real IP address that the user logged in from. This fake IP address can later be displayed in the My Account popup that shows the IP address that was used to log in.
References
Configurations
No configuration.
History
28 Dec 2024, 19:15
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.4 |
CWE | CWE-290 |
27 Dec 2024, 20:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-12-27 20:15
Updated : 2024-12-28 19:15
NVD link : CVE-2024-54450
Mitre link : CVE-2024-54450
CVE.ORG link : CVE-2024-54450
JSON object : View
Products Affected
No product.
CWE
CWE-290
Authentication Bypass by Spoofing