An issue was discovered in pretix before 2023.7.1. Incorrect parsing of configuration files causes the application to trust unchecked X-Forwarded-For headers even though it has not been configured to do so. This can lead to IP address spoofing by users of the application.
Advisories
Source ID Title
EUVD EUVD EUVD-2023-0207 An issue was discovered in pretix before 2023.7.1. Incorrect parsing of configuration files causes the application to trust unchecked X-Forwarded-For headers even though it has not been configured to do so. This can lead to IP address spoofing by users of the application.
Github GHSA Github GHSA GHSA-j9gq-w73w-9h6c pretix potential IP address spoofing vulnerability
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 23 Sep 2024 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-290
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-09-23T16:19:47.110Z

Reserved: 2023-09-29T00:00:00

Link: CVE-2023-44463

cve-icon Vulnrichment

Updated: 2024-08-02T20:07:33.439Z

cve-icon NVD

Status : Modified

Published: 2023-10-02T20:15:10.277

Modified: 2024-11-21T08:25:55.877

Link: CVE-2023-44463

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.