vendor:
http-protection (Crystal Shard)
by:
Halis Duraki
7.5
CVSS
HIGH
IP Spoofing Bypass
16
CWE
Product Name: http-protection (Crystal Shard)
Affected Version From: http-protection <= 0.2.0
Affected Version To:
Patch Exists: NO
Related CWE:
CPE: a:rogeriozambon:http-protection:0.2.0
Platforms Tested:
2020
Crystal Shard http-protection 0.2.0 – IP Spoofing Bypass
The exploit allows bypassing the IP spoofing protection in Crystal Shard http-protection version 0.2.0. By hardcoding values in the X-* headers, an attacker can bypass the middleware's detection of spoofing attacks.
Mitigation:
The vendor has not released a patch for this vulnerability. Users are advised to update to a version higher than 0.2.0 or implement additional security measures to mitigate the risk of IP spoofing.